Back to skill

Security audit

Vincent - Brave Search

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed Brave Search integration, but it also enables unpinned runtime CLI execution and autonomous wallet-funded credit purchases that exceed ordinary search needs.

Review before installing. Use this only if you trust the Vincent CLI and service, pin or preinstall a reviewed CLI version, keep search credentials separate from payment credentials, and do not expose a wallet or enable auto-top-up unless strict external spend limits and human approval are enforced.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:72
Finding

Mutable npm Package Is Downloaded and Executed at Runtime

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:184
Finding

Search Skill Enables Autonomous Cryptocurrency Spending Beyond Necessary Privileges

Content
View full analysis
``` ### Purchase Credits via x402 (USDC on Base) ```bash npx @vincentai/cli@latest credits add --key-id --amount 10 ``` **How it works:** 1. The CLI sends a POST request to the x402 credit endpoint 2. The server returns HTTP 402 with a dynamic USDC deposit address on Base 3. The CLI signs the payment using your agent's wallet 4. The CLI retries the request with the payment proof 5. The server verifies the payment and adds credits to your account ``` The documented automatic replenishment pattern further encourages unattended spending: ```bash BALANCE=$(npx @vincentai/cli@latest credits balance --key-id --json | jq -r '.balance') if (( $(echo "$BALANCE < 2.00" | bc -l) )); then npx @vincentai/cli@latest credits add --key-id --amount 10 fi ``` ### Technical Analysis The declared purpose of the Skill is Brave web and news search. That functionality requires authorization to submit search requests and deduct previously funded service credit, but it does not inherently require access to a cryptocurrency wallet or authority to sign blockchain transactions. The instructions explicitly allow the agent to purchase credits with “no human intervention required.” They also provide an automatic replenishment pattern that initiates a payment whenever the reported balance is below a threshold. No per-transaction confirmation, cumulative spending ceiling, payment-frequency limit, independently verified recipie ...[truncated 1877 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Autonomous wallet-based credit purchase is not necessary to perform web search and creates a direct path from benign user intent to financial execution. In context, this is especially dangerous because the skill is agent-oriented and encourages unattended operation, so a prompt-triggered or compromised agent could spend cryptocurrency without meaningful user review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad and generic, making it more likely the skill activates in contexts where the user did not intend to invoke this particular integration. Because the skill includes secret creation and payment-related capabilities, accidental activation is more dangerous than for a narrow read-only skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation claims human oversight as part of the security model, but later sections explicitly enable autonomous credit purchases without human intervention. This inconsistency can mislead reviewers and users about actual risk, causing the skill to be deployed under weaker safeguards than its behavior warrants.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill metadata permits execution of Bash(npx:@vincentai/cli*), and this occurrence documents invoking the package without a pinned immutable version. Unpinned npx execution can pull whatever package version is current at runtime, creating a supply-chain risk where a compromised or malicious upstream release gains code execution in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command uses npx @vincentai/cli in a way that may resolve a remote package version at execution time rather than a reviewed local artifact. In an agent skill, that means the trust boundary extends to the npm registry and package publisher account, enabling arbitrary code execution if the dependency is ever hijacked.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documented use of npx @vincentai/cli without an immutable pin creates a runtime package substitution risk. Because the skill is intended for autonomous operation, any compromise of the package distribution channel could directly affect unattended agents and any secrets or wallets available to them.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This occurrence continues the pattern of unpinned npx execution for a privileged CLI that manages secrets and API access. The combination of secret management and dynamic package resolution materially raises the impact of supply-chain compromise beyond a normal documentation issue.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command invokes the same unpinned external CLI in the context of key recovery (secret relink), which could expose or overwrite authentication state if the package is compromised. Since relinking re-establishes access, an attacker-controlled package could capture tokens or mint unauthorized access paths.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a web/news search capability, but the documentation expands its scope into credit purchasing, payment orchestration, and wallet interactions. This broadening violates least privilege and increases the blast radius: a skill invoked for information retrieval can now spend funds and interact with payment infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes autonomous wallet-based credit purchasing without a prominent user warning about spending, wallet usage, or transaction signing risk. In an autonomous agent context, lack of conspicuous warning materially increases the chance of users enabling a capability that can move funds without understanding the consequences.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The balance-check command again relies on an unpinned npm package executed via npx, preserving the same supply-chain code execution risk. In this skill, the CLI is trusted to access account and billing state, so compromise could leak financial or credential information.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Here the unpinned npx package is used for credits add, which interacts with wallet/payment flows. A compromised upstream package could trigger fraudulent payment behavior, redirect funds, exfiltrate wallet material, or manipulate transaction details, making the financial impact especially severe.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Card checkout initiation is outside the stated search purpose and enables the skill to generate payment flows for the user. Even if payment entry occurs through Stripe, a search skill should not be able to trigger billing links by default because it expands the capability from retrieval to monetization and phishing-adjacent behaviors.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This checkout command also uses dynamic npx execution, extending supply-chain risk into billing and payment initiation. Even if card entry happens elsewhere, a compromised CLI could generate phishing checkout URLs or misdirect the user to attacker-controlled payment pages.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The auto-replenish example embeds unpinned npx usage in a scripted flow that may run automatically when credit is low. That combines supply-chain risk with unattended financial actions, so a malicious package update could repeatedly execute unauthorized top-ups or other arbitrary commands without immediate human review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This auto-top-up invocation uses unpinned npx for a payment action in a conditional automation block. Because it is designed to execute when balance thresholds are crossed, a compromised package could silently escalate from search functionality into unauthorized recurring spending or broader host compromise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.