Back to skill

Security audit

MochiPay Integration

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed MochiPay payment-integration guide with an optional offline checker, and its sensitive payment-related behavior is bounded by user authorization and explicit safety limits.

Install only in a store or codebase you are authorized to change. Keep MochiPay API keys, secrets, wallet recovery phrases, customer data, and private configs out of chat; enter them directly in your own backend or dashboard. Before enabling production payments, verify official downloads and hashes, run project tests, confirm callback/return handling, and treat the offline checker as a preliminary aid rather than proof that payments work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description promises a substantive MochiPay integration capability for multiple server/mobile stacks, including implementing payment flows and verifying operational behaviors. The actual code only performs offline validation of a sanitized configuration file and displays local reference metadata. While the domain is related to MochiPay integration, the primary purpose is materially narrower and lacks the declared functional capabilities. Therefore the description overstates what the code chunk actually does.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/developer-examples.md (reported line 13)May include surrounding context.

md
## Mobile implementation

Select the existing Swift or Kotlin source project. Set only the merchant HTTPS backend origin in the app. Keep API key/secret exclusively on that backend. Treat the independent staging access token as demo-only and replace it with the merchant app's real account session. Retain request_id and original method across retries/restarts; mode/language changes do not change the order. Protect saved capability URLs; never log them. Validate returned checkout URLs against the configured origin and /checkout path.

ON_SITE opens the merchant-local payment dialog in WKWebView/AndroidWebView. Restrict navigation to the merchant HTTPS origin and do not install a JavaScript/native success bridge. HPP opens the merchant redirect route in the external browser. On app foreground or explicit refresh, query the merchant backend; never infer payment from browser return. Active polls are15 seconds, not a background mobile job. Backend notification verification continues if the app closes.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/installation.md (reported line 10)May include surrounding context.

md
## Claude

Enable code execution/file creation if the account/workspace permits. Open Customize > Skills > + > Create skill > Upload a skill, upload the complete ZIP and enable it. Ask: "Use MochiPay Integration to connect my store." A conversation attachment is not persistent installation.
Official: https://support.claude.com/en/articles/12512180-use-skills-in-claude

## Claude Code

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/installation.md (reported line 15)May include surrounding context.

md
## Claude Code

Extract to ~/.claude/skills/integrate-mochipay/SKILL.md (personal) or <project>/.claude/skills/integrate-mochipay/SKILL.md (project). Avoid duplicate nested folders. Invoke /integrate-mochipay or request MochiPay setup. Follow client refresh guidance if absent.
Official: https://code.claude.com/docs/en/skills

## Codex CLI / IDE

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/installation.md (reported line 20)May include surrounding context.

md
## Claude Code

Extract to ~/.claude/skills/integrate-mochipay/SKILL.md (personal) or <project>/.claude/skills/integrate-mochipay/SKILL.md (project). Avoid duplicate nested folders. Invoke /integrate-mochipay or request MochiPay setup. Follow client refresh guidance if absent.
Official: https://code.claude.com/docs/en/skills

## Codex CLI / IDE

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON manifest includes a predefined "buyer_languages" list, effectively constraining locale/language behavior in natural-language-facing UI metadata. The file does not indicate that users can choose their preferred language or that the locale restriction is justified as region-specific, which can conflict with the policy against forcing language/locale without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction says users can 'request MochiPay setup,' which is broad natural language and does not clearly delimit which phrasings should or should not invoke the skill. Because this is a markdown installation file, ambiguous invocation wording can increase the chance of unintended activation compared with a narrowly specified command or trigger list.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.