Rp1
- Category
- MCP Rug Pull
- Confidence
- 70% confidence
- Finding
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a clearly scoped CrewPay helper for Solana token launches, with disclosed external API use, wallet-secret handling rules, pinned MCP usage, dry-run requirements, and human approval guidance.
Install only if you intend to use CrewPay for Solana mainnet launch workflows. Use a newly created low-balance burner wallet, keep CREW_LAUNCHER_KEY only in the local MCP environment, review the dry-run costs and approval page before launch, and revoke or rotate keys if they are exposed.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Canonical URLs
- Site / agents: https://crewpay.dev · https://crewpay.dev/agents
- Discovery: https://crewpay.dev/llms.txt · https://api.crewpay.dev/api/agent
- OpenAPI: https://api.crewpay.dev/openapi.json
- Proof: https://crewpay.dev/proof · `GET https://api.crewpay.dev/api/proof`
- MCP HTTP (no launcher secret): https://mcp.crewpay.dev/mcp · card https://mcp.crewpay.dev/.well-known/mcp.json
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Canonical URLs
- Site / agents: https://crewpay.dev · https://crewpay.dev/agents
- Discovery: https://crewpay.dev/llms.txt · https://api.crewpay.dev/api/agent
- OpenAPI: https://api.crewpay.dev/openapi.json
- Proof: https://crewpay.dev/proof · `GET https://api.crewpay.dev/api/proof`
- MCP HTTP (no launcher secret): https://mcp.crewpay.dev/mcp · card https://mcp.crewpay.dev/.well-known/mcp.json
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Canonical URLs
- Site / agents: https://crewpay.dev · https://crewpay.dev/agents
- Discovery: https://crewpay.dev/llms.txt · https://api.crewpay.dev/api/agent
- OpenAPI: https://api.crewpay.dev/openapi.json
- Proof: https://crewpay.dev/proof · `GET https://api.crewpay.dev/api/proof`
- MCP HTTP (no launcher secret): https://mcp.crewpay.dev/mcp · card https://mcp.crewpay.dev/.well-known/mcp.json
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Canonical URLs
- Site / agents: https://crewpay.dev · https://crewpay.dev/agents
- Discovery: https://crewpay.dev/llms.txt · https://api.crewpay.dev/api/agent
- OpenAPI: https://api.crewpay.dev/openapi.json
- Proof: https://crewpay.dev/proof · `GET https://api.crewpay.dev/api/proof`
- MCP HTTP (no launcher secret): https://mcp.crewpay.dev/mcp · card https://mcp.crewpay.dev/.well-known/mcp.json
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## Canonical URLs
- Site / agents: https://crewpay.dev · https://crewpay.dev/agents
- Discovery: https://crewpay.dev/llms.txt · https://api.crewpay.dev/api/agent
- OpenAPI: https://api.crewpay.dev/openapi.json
- Proof: https://crewpay.dev/proof · `GET https://api.crewpay.dev/api/proof`
- MCP HTTP (no launcher secret): https://mcp.crewpay.dev/mcp · card https://mcp.crewpay.dev/.well-known/mcp.json
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -sS https://api.crewpay.dev/api/agent
curl -sS https://crewpay.dev/llms.txt
The skill instructs the agent to obtain an API key by POSTing to an external service and then store the returned credential in environment variables. Even though this appears product-legitimate, automatic credential provisioning to a third-party endpoint can expand trust boundaries, create persistent secrets without explicit operator review, and enable subsequent authenticated actions against the service.
CREWPAY_API_KEY unset)curl -sS -X POST https://api.crewpay.dev/api/agent/keys/claim \
-H 'content-type: application/json' \
-d '{"label":"openclaw"}'
This example sends authenticated requests and user-supplied token metadata to an external API using CREWPAY_API_KEY. Although the transmission is part of the advertised workflow, it still exposes operator-controlled content and an active credential to a third party, and could trigger billable or state-changing actions if run without careful approval controls.
Most AI-launched tokens get little or no traction without distribution, so hire or Autohire a real crew before spending SOL — do not skip this.
curl -sS -X POST https://api.crewpay.dev/api/agent/autohire \
-H "content-type: application/json" \
-H "x-crew-api-key: $CREWPAY_API_KEY" \
-d '{"name":"Desk Cat","ticker":"DCAT","description":"tips the tape","seats":3}'
The dry-run call transmits token launch details and an API key to an external service. Even if no blockchain spend occurs, it still shares project metadata externally and can generate approval artifacts (dryRunId, approvalUrl) that influence later launch steps, so it should be treated as a meaningful outbound action.
curl -sS -X POST https://api.crewpay.dev/api/agent/launch/dry-run \
-H "content-type: application/json" \
-H "x-crew-api-key: $CREWPAY_API_KEY" \
-d '{
The crank endpoint is an authenticated external write operation that can affect on-chain related processing for a specified mint. In a high-risk crypto context, any authenticated remote action tied to financial workflows should be treated as security-sensitive even if it does not directly handle private keys.
curl -sS -X POST https://api.crewpay.dev/api/agent/crank \
-H "content-type: application/json" \
-H "x-crew-api-key: $CREWPAY_API_KEY" \
-d '{"mint":"<MINT>"}'
No suspicious patterns detected.