Back to skill

Security audit

LNBits Wallet wtih QR Code

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent LNbits wallet helper, but it can send real Lightning payments with only prompt-level confirmation and weak endpoint scoping for an admin key.

Install only if you are comfortable giving the assistant an LNbits admin key and you will supervise every payment. Use a dedicated wallet with limited funds, configure only a trusted HTTPS LNbits URL, avoid pasting secrets into chat, and treat payment approval prompts as mandatory because the CLI itself does not enforce confirmation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lnbits_cli.py:17
Finding

LNbits administrator API key may be exposed through insecure endpoints or cross-origin redirects

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:5
Finding

Unpinned QR-code dependency creates avoidable supply-chain exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tainted flow: 'req' from os.getenv (line 140, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/lnbits_cli.py (reported line 97)May include surrounding context.

python
req = urllib.request.Request(url, method=method, headers=headers, data=body)
    try:
        with urllib.request.urlopen(req, timeout=20) as resp:
            return json.loads(resp.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        error_body = e.read().decode("utf-8", errors="replace")

Tainted flow: 'req' from os.getenv (line 140, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/lnbits_cli.py (reported line 146)May include surrounding context.

python
req = urllib.request.Request(url, method=method, headers=headers, data=body)
    try:
        with urllib.request.urlopen(req, timeout=20) as resp:
            return json.loads(resp.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        error_body = e.read().decode("utf-8", errors="replace")

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description says the skill manages balance, paying, and invoice creation, but the content also supports wallet creation, invoice decoding, and local QR generation/storage. This mismatch is risky because reviewers and policy engines may approve the skill for narrower wallet operations while overlooking account provisioning and extra data-handling behaviors that affect secrets, local files, and payment metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The pay command sends funds immediately when provided a BOLT11 invoice, with no built-in confirmation step, amount preview, or recipient verification. In an agent setting this is especially dangerous because prompt injection, tool misuse, or operator error could cause irreversible Lightning payments.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes shell commands, reads environment-provided secrets, accesses the network, and writes local QR image files, yet it does not declare any explicit tool scope or allowed-tools policy. In a wallet-management skill, this omission is dangerous because it leaves a high-risk payment and secret-handling workflow under-bounded, increasing the chance an agent can use broader capabilities than intended or execute sensitive actions without clear sandboxing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description says it manages an LNbits wallet via balance, pay, and invoice operations, but the code also exposes account/wallet creation. This hidden capability expands the trust boundary and can trigger unexpected remote-side actions, making it easier for an agent or user to invoke functionality they were not informed the skill possessed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The create command performs a remote account/wallet creation action without any visible disclosure or confirmation in the tool flow. While less severe than direct payment, it still causes external side effects and transmits user-supplied data to a third-party LNbits instance, which may be unexpected given the stated skill scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code supports standalone QR generation and writes PNG files to disk, but this behavior is not disclosed in the skill description. Undisclosed filesystem writes are risky in agent environments because they create side effects and artifacts that users may not expect or approve.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.