T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned npm Package Executes with Access to Payment Credentials and Purchasing Operations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This payment skill is coherent in purpose, but it asks users to run an unpinned npm payment tool, can complete real purchases, offers HTTP MCP access, and makes an overbroad local-only security claim despite mentioning Browserbase.
Review carefully before installing. Only use this on a trusted device, pin or independently verify the AgentPay package before running it, avoid HTTP MCP mode unless you can secure its bind address and authentication, and confirm exact merchant, item, amount, URL, shipping details, and budget impact before approving any transaction.
SKILL.md:5Unpinned npm Package Executes with Access to Payment Credentials and Purchasing Operations
references/workflow.md:29Cloud Browser Option Conflicts with the Claimed Local-Only Security Model
The skill description is extremely broad and matches common requests like buying products, booking travel, or subscribing to services, which increases the chance of over-invocation by an orchestrating agent. In a payment-capable skill, over-broad routing is dangerous because accidental invocation can escalate ordinary shopping discussion into real-world purchase actions and expose users to unauthorized spending workflows.
The skill instructs users to run npx agentpay without pinning an exact package version, which allows the fetched code to change over time and exposes users to supply-chain compromise if the npm package is hijacked or a malicious version is published. In this skill, the risk is amplified because the tool handles purchasing workflows, local encrypted credentials, and browser-driven checkout, so executing an unexpected version could lead to unauthorized purchases or local data access.
This unpinned npx agentpay command performs budget configuration but still relies on downloading/executing whatever version npm resolves at the time. Because the package is security-sensitive and connected to payment authorization logic, a compromised release could alter limits, exfiltrate local secrets, or misrepresent transaction controls.
The purchase proposal flow uses npx agentpay buy without version pinning, creating a supply-chain execution point in a payment context. If an attacker controls the published package or a dependency, they could modify the approval workflow, tamper with purchase details, or execute arbitrary code on the user's machine.
Listing pending purchases via an unpinned npx invocation is still unsafe because it executes package code before showing status. Even seemingly read-only commands can be abused by a malicious package version to run arbitrary local actions or harvest environment data.
Approval of a transaction through an unpinned npx agentpay approve command is especially dangerous because it sits directly on the authorization path for purchases. A malicious or swapped package version could approve the wrong transaction, alter checkout behavior, or perform unauthorized actions while appearing legitimate.
npx agentpay status is unpinned and therefore remains a supply-chain execution risk despite being framed as a diagnostic command. In this skill, status commands may expose transaction metadata and run in an environment with access to local wallet state, increasing the consequences of arbitrary code execution.
The history command is also invoked through unpinned npx, enabling arbitrary code execution from a mutable package source. Since transaction history may reveal merchant behavior, amounts, and operational context, a compromised package could leak sensitive financial metadata.
The README advertises an HTTP MCP server mode but provides no warning about bind scope, authentication, network reachability, or the sensitivity of exposed purchase operations. Because this skill can initiate or manage real transactions, exposing MCP over HTTP without strong defaults and user-facing warnings could allow other local or remote processes to invoke payment-related tools or harvest transactional data.
Launching the MCP server with npx agentpay mcp without version pinning is a significant risk because it exposes tool operations that can initiate or manage purchases. A malicious package version could register backdoored tools, alter tool semantics, or abuse the agent integration boundary for unauthorized actions.
The HTTP-mode MCP server command is both unpinned and network-exposed, combining supply-chain risk with remote accessibility concerns. If a malicious version is fetched, it could intentionally open unsafe endpoints, weaken authentication assumptions, or expose purchase-related capabilities over the network.
The quick-action buy example repeats the unpinned npx pattern in a highly likely copy-paste path for users. Because this is a purchase-initiating command, a compromised package version could directly manipulate transaction creation or execute arbitrary code under the guise of normal checkout automation.
The pending command in the quick-actions table is another executable example that relies on mutable package resolution. Repetition across documentation increases the chance that users normalize insecure invocation patterns and repeatedly execute unverified code.
Budget inspection through an unpinned package still creates a code execution opportunity from a non-immutable source. Given the financial nature of the skill, a malicious package could misreport limits or alter local state to facilitate overspending or conceal abuse.
The transaction history quick action executes unpinned package code in a context containing financial metadata. Although the command appears informational, a compromised package could leak history contents or stage further attacks on the local machine.
Opening the dashboard via unpinned npx agentpay dashboard creates another supply-chain execution point, potentially giving malicious code a path into browser-based flows and transaction interfaces. In a purchasing skill, any UI-launching command can become a vehicle for phishing, tampering, or local compromise if the package source is not fixed.
The troubleshooting guidance tells users to run npx agentpay status after checkout failures, again without a fixed version. This is risky because users are especially likely to trust and execute support commands during incidents, giving a compromised package an opportunity to exploit a high-trust moment.
The setup command explicitly handles payment credentials and creates an encrypted local vault, but the reference omits a prominent warning about the sensitivity of the information being entered and stored. In a payment-focused skill, this can mislead users into entering financial credentials without understanding local storage and trust implications, increasing the risk of unsafe use on shared or compromised systems.
The approve command description says it triggers headless browser checkout, but the CLI reference does not present this as a strong execution warning despite it causing a real purchase to be completed. In the context of an agent purchasing tool, understated documentation can cause accidental approvals or underestimation of the consequences of running the command.
No suspicious patterns detected.