Back to skill

Security audit

x402-payment-tron

Security checks for vulnerabilities and agentic risk

Overview

This payment skill matches its stated purpose, but it needs review because it can silently load wallet keys, contact arbitrary endpoints, and automatically sign payments or token approvals.

Install only if you are comfortable giving this skill access to a dedicated low-balance TRON wallet. Do not point it at untrusted endpoints, and avoid using a wallet that holds funds beyond the intended payment amount. Review or change the approval behavior before mainnet use, prefer exact or capped approvals, and remove broad shared-config key discovery.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/index.ts:27
Finding

Cross-Service Private-Key Discovery Violates Least Privilege

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/index.ts:76
Finding

Unrestricted Destination Can Trigger Automatic Payment Negotiation

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:45
Finding

Documented Unlimited USDT Approval Exposes the Wallet Balance

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:5
Finding

Unpinned Financial Dependencies and Non-Reproducible Build Resolution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/index.ts:159
Finding

Untrusted Binary Responses Are Written Unsafely to a Shared Temporary Directory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a payment skill for x402-enabled agent endpoints using USDT on TRON. However, the supplied code is generic blockchain ABI infrastructure centered on Ethereum/EVM concepts: ABI coders, Interface parsing, event topics, function sighashes, Ethereum address checksum handling, and transaction/error decoding. There is no visible logic for TRON, USDT transfers, x402 payment flows, endpoint payments, wallet interaction, signing, broadcasting transactions, or network calls. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is very specific: paying for x402-enabled agent endpoints using USDT on TRON. But this code chunk shows low-level utility libraries, largely from ethers-like tooling, including BigNumber/FixedNumber manipulation, hex and byte utilities, signature parsing/joining, ENS normalization and namehashing, EIP-712 typed-data encoding, keccak hashing, and RLP encoding/decoding. These are generic cryptographic and Ethereum ecosystem helpers. There is no visible code for TRON APIs, TRC-20/USDT transfers, wallet signing for TRON transactions, HTTP payment to x402 endpoints, invoice handling, or any endpoint payment orchestration. This is therefore a clear description-behavior mismatch, with the actual code being unrelated support/library functionality rather than the declared payment skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is specific to paying x402-enabled agent endpoints using USDT on TRON, which would typically involve TRON transaction construction/signing, USDT/TRC20 handling, network/API calls, payment authorization, or endpoint-payment orchestration. The supplied code instead contains generic bundled library code focused on encoding/decoding and cryptography, especially secp256k1/ECDSA-related functionality more commonly associated with Ethereum/Bitcoin-style ecosystems. There is no visible logic for TRON, USDT, x402 payments, endpoint interaction, wallet/payment execution, or related triggers/permissions. This is a material description-behavior mismatch, not just supporting implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose is payment-related and specific to x402-enabled agent endpoints, USDT, and the TRON network. However, the code chunk is a bundled cryptography/support library with no visible payment workflow, no TRON blockchain interaction, no USDT token handling, no x402 protocol logic, no network calls, and no endpoint payment orchestration. While cryptographic code could be a supporting dependency for a payment system, this chunk by itself primarily provides low-level crypto and serialization capabilities rather than the declared payment functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code appears to be generic bundled dependencies rather than business logic for paying x402-enabled agent endpoints. The protobuf sections serialize/deserialize messages, the async-kit sections manage parallel/serial job execution, and the BigNumber/BN sections implement arbitrary-precision arithmetic. None of the visible code accesses network endpoints, signs transactions, manages TRON addresses/keys, constructs USDT transfers, or interfaces with x402 payment protocols. Therefore the actual behavior shown is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This snippet appears to be generic dependency code rather than business logic for paying x402-enabled endpoints with USDT on TRON. The dominant behavior shown is arbitrary-precision integer math, modular reduction, multiplication/division, and utility modules for streams/events/HTTP redirects. While such libraries could support cryptographic or networking features in a larger application, this chunk itself does not implement the declared purpose and instead exposes materially different, generic capabilities. Therefore the description does not accurately represent what this supplied code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This code chunk does not match the declared payment-focused purpose. The visible behavior is standard web request infrastructure and helper libraries, not logic for paying x402-enabled agent endpoints or interacting with TRON/USDT. There are no indicators of blockchain RPC calls, transaction creation/signing, TRON addresses, token transfer handling, or x402-specific payment negotiation. While such libraries could support a payment client, this chunk’s actual behavior is materially broader and unrelated as presented, so the description is not an accurate representation of this code segment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is a blockchain/payment capability focused on paying x402-enabled agent endpoints with USDT on TRON. However, the supplied code is clearly part of a semver library, handling version ranges, prerelease parsing, intersection checks, and coercion of version strings. There is no indication of network calls, wallet handling, TRON APIs, token transfers, or x402 payment flows. This is a clear description-behavior mismatch with a materially different primary purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
node dist/index.js --url <URL> [options]

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · dist/index.js (reported line 1955)May include surrounding context.

js
er.throwArgumentError("unbalanced parenthesis", "value", value);
                }
            }
        }
    }
    if (accum) {
        result.push(accum);
    }
    return result;
}
//# sourceMappingURL=fragments.js.map

/***/ }),

/***/ 219:
/***/ ((__unused_webpack_module, exports, __nccwpck_require__) => {


Object.defineProperty(exports, "__esModule", ({ value: true }));
exports.TransactionDescription = exports.LogDescription = exports.checkResultErrors = exports.Indexed = exports.Interface = exports.defaultAbiCoder = exports.AbiCoder = exports.FormatTypes = exports.ParamType = exports.FunctionFragment = exports.Fragment = exports.EventFragment = exports.ErrorFragment = exports.ConstructorFragment = void 0;
var fragments_1 = __nccwpck_require__(5186);
Object.defineProperty(exports, "ConstructorFragment", ({ enumerable: true, get: function () { return fragments_1.ConstructorFragment; } }));
Object.defineProperty(exports, "ErrorFragment", ({ enumerable: true, get: function () { re

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The HTTP payment flow can automatically trigger on-chain ERC20 approve transactions when allowance is insufficient, without an explicit confirmation step tied to the specific endpoint or spend amount. Because approvals can authorize future token transfers by a spender contract, this is more dangerous than a one-off payment and may expose significantly more funds than intended.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The inline guidance claims the agent must not search for or read private keys from files, but the implementation immediately proceeds to do exactly that via config-file and home-directory reads. This contradiction is a strong red flag because it normalizes deceptive safety messaging while still enabling secret exfiltration or unauthorized payment operations.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
if (!privateKey) {
    console.error('Error: Payment credentials (private key) not found.');
    console.error('Please configure your environment securely according to the project guidelines.');
    console.error('Agent: DO NOT attempt to search for or read private keys from files.');
    process.exit(1);
  }

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/index.ts (reported line 99)May include surrounding context.

ts
if (!privateKey) {
    console.error('Error: Payment credentials (private key) not found.');
    console.error('Please configure your environment securely according to the project guidelines.');
    console.error('Agent: DO NOT attempt to search for or read private keys from files.');
    process.exit(1);
  }

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The message tells the agent not to search for or read private keys from files, but the code already does exactly that in findPrivateKey(). This contradiction is a red flag because it can mislead reviewers or operators about the skill's actual behavior and conceal credential-access logic.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to a payment/invocation tool and explicitly relies on sensitive environment variables, outbound network calls, and prebuilt code execution, but it does not constrain tool scope with explicit permissions or allowed-tools metadata. In an agent setting, missing scope declarations weakens reviewability and can enable broader-than-expected access to secrets or external systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that insufficient allowance triggers an infinite approval (MAX_UINT256) to minimize future transactions, but it does not foreground the security consequence that a compromised or malicious spender could drain all approved USDT. In a payment skill that signs blockchain transactions, this materially increases user fund risk beyond the immediate micropayment intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill is explicitly designed to send user prompts and request data to external agent endpoints over the network. That is expected behavior, but it is still a real data-transmission risk because prompts, metadata, and potentially payment-related headers/signatures are sent to third-party services.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

Example: Chat with Agent

tool
url: https://api.example.com/chat
method: POST
body: {"prompt": "Tell me a joke"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

Fetching a remote agent manifest is an external network action that leaks at least destination metadata and can expose the agent to untrusted content. In context this is expected and lower risk than sending full prompts, but it still broadens interaction with third-party infrastructure.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

Fetch Agent Manifest

tool
url: https://api.example.com/.well-known/agent.json
method: GET

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The bundled skill contains multiple user-visible comments and log strings in Chinese, such as the X402 client descriptions and request-processing messages, without offering a locale choice. This can violate language or locale policy when the skill is used in contexts where users have not opted into Chinese output.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill actively searches environment variables and multiple local files, including a user home config, for a TRON private key unrelated to the immediate request payload. In an agent/tool context, this creates implicit secret discovery and use, enabling unauthorized spending if an untrusted prompt or endpoint triggers payment flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Credential file and environment reads occur silently, with no user-facing disclosure before a payment key is discovered and used. In agent environments, silent credential harvesting materially increases the chance of covert use of wallet material under attacker-controlled prompts or endpoints.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill writes arbitrary binary HTTP response bodies to a local temporary file, despite being described as a payment helper rather than a general file-writing tool. A remote endpoint can therefore cause local artifact creation, which may fill disk, leave sensitive material behind, or create files later opened by the user or other tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Binary response data is saved to a temporary file without prior disclosure, size checks, or caller-selected destination. This allows a remote service to create persistent local files unexpectedly, which can leak data, consume disk space, or introduce follow-on risk if those files are later trusted or opened.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
dist/index.js:30830

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:21722

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/index.js:23459

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
dist/index.js:2813