Back to skill

Security audit

CrewPay

Security checks for vulnerabilities and agentic risk

Overview

The skill is a clearly scoped CrewPay helper for Solana token launches, with disclosed external API use, wallet-secret handling rules, pinned MCP usage, dry-run requirements, and human approval guidance.

Install only if you intend to use CrewPay for Solana mainnet launch workflows. Use a newly created low-balance burner wallet, keep CREW_LAUNCHER_KEY only in the local MCP environment, review the dry-run costs and approval page before launch, and revoke or rotate keys if they are exposed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (11)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
## Canonical URLs

- Site / agents: https://crewpay.dev · https://crewpay.dev/agents
- Discovery: https://crewpay.dev/llms.txt · https://api.crewpay.dev/api/agent
- OpenAPI: https://api.crewpay.dev/openapi.json
- Proof: https://crewpay.dev/proof · `GET https://api.crewpay.dev/api/proof`
- MCP HTTP (no launcher secret): https://mcp.crewpay.dev/mcp · card https://mcp.crewpay.dev/.well-known/mcp.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
## Canonical URLs

- Site / agents: https://crewpay.dev · https://crewpay.dev/agents
- Discovery: https://crewpay.dev/llms.txt · https://api.crewpay.dev/api/agent
- OpenAPI: https://api.crewpay.dev/openapi.json
- Proof: https://crewpay.dev/proof · `GET https://api.crewpay.dev/api/proof`
- MCP HTTP (no launcher secret): https://mcp.crewpay.dev/mcp · card https://mcp.crewpay.dev/.well-known/mcp.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
## Canonical URLs

- Site / agents: https://crewpay.dev · https://crewpay.dev/agents
- Discovery: https://crewpay.dev/llms.txt · https://api.crewpay.dev/api/agent
- OpenAPI: https://api.crewpay.dev/openapi.json
- Proof: https://crewpay.dev/proof · `GET https://api.crewpay.dev/api/proof`
- MCP HTTP (no launcher secret): https://mcp.crewpay.dev/mcp · card https://mcp.crewpay.dev/.well-known/mcp.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
## Canonical URLs

- Site / agents: https://crewpay.dev · https://crewpay.dev/agents
- Discovery: https://crewpay.dev/llms.txt · https://api.crewpay.dev/api/agent
- OpenAPI: https://api.crewpay.dev/openapi.json
- Proof: https://crewpay.dev/proof · `GET https://api.crewpay.dev/api/proof`
- MCP HTTP (no launcher secret): https://mcp.crewpay.dev/mcp · card https://mcp.crewpay.dev/.well-known/mcp.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

md
## Canonical URLs

- Site / agents: https://crewpay.dev · https://crewpay.dev/agents
- Discovery: https://crewpay.dev/llms.txt · https://api.crewpay.dev/api/agent
- OpenAPI: https://api.crewpay.dev/openapi.json
- Proof: https://crewpay.dev/proof · `GET https://api.crewpay.dev/api/proof`
- MCP HTTP (no launcher secret): https://mcp.crewpay.dev/mcp · card https://mcp.crewpay.dev/.well-known/mcp.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

Discover (no auth)

bash
curl -sS https://api.crewpay.dev/api/agent
curl -sS https://crewpay.dev/llms.txt

External Transmission

Medium
Category
Data Exfiltration
Confidence
73% confidence
Finding

The skill instructs the agent to obtain an API key by POSTing to an external service and then store the returned credential in environment variables. Even though this appears product-legitimate, automatic credential provisioning to a third-party endpoint can expand trust boundaries, create persistent secrets without explicit operator review, and enable subsequent authenticated actions against the service.

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

Claim API key (if CREWPAY_API_KEY unset)

bash
curl -sS -X POST https://api.crewpay.dev/api/agent/keys/claim \
  -H 'content-type: application/json' \
  -d '{"label":"openclaw"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This example sends authenticated requests and user-supplied token metadata to an external API using CREWPAY_API_KEY. Although the transmission is part of the advertised workflow, it still exposes operator-controlled content and an active credential to a third party, and could trigger billable or state-changing actions if run without careful approval controls.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

Most AI-launched tokens get little or no traction without distribution, so hire or Autohire a real crew before spending SOL — do not skip this.

bash
curl -sS -X POST https://api.crewpay.dev/api/agent/autohire \
  -H "content-type: application/json" \
  -H "x-crew-api-key: $CREWPAY_API_KEY" \
  -d '{"name":"Desk Cat","ticker":"DCAT","description":"tips the tape","seats":3}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The dry-run call transmits token launch details and an API key to an external service. Even if no blockchain spend occurs, it still shares project metadata externally and can generate approval artifacts (dryRunId, approvalUrl) that influence later launch steps, so it should be treated as a meaningful outbound action.

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

Dry-run (mandatory; no launcher secret)

bash
curl -sS -X POST https://api.crewpay.dev/api/agent/launch/dry-run \
  -H "content-type: application/json" \
  -H "x-crew-api-key: $CREWPAY_API_KEY" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The crank endpoint is an authenticated external write operation that can affect on-chain related processing for a specified mint. In a high-risk crypto context, any authenticated remote action tied to financial workflows should be treated as security-sensitive even if it does not directly handle private keys.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

Crank + proof (no launcher secret required)

bash
curl -sS -X POST https://api.crewpay.dev/api/agent/crank \
  -H "content-type: application/json" \
  -H "x-crew-api-key: $CREWPAY_API_KEY" \
  -d '{"mint":"<MINT>"}'

Static analysis

No suspicious patterns detected.