Back to skill

Security audit

Agentpay

Security checks for vulnerabilities and agentic risk

Overview

This payment skill is coherent in purpose, but it asks users to run an unpinned npm payment tool, can complete real purchases, offers HTTP MCP access, and makes an overbroad local-only security claim despite mentioning Browserbase.

Review carefully before installing. Only use this on a trusted device, pin or independently verify the AgentPay package before running it, avoid HTTP MCP mode unless you can secure its bind address and authentication, and confirm exact merchant, item, amount, URL, shipping details, and budget impact before approving any transaction.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:5
Finding

Unpinned npm Package Executes with Access to Payment Credentials and Purchasing Operations

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/workflow.md:29
Finding

Cloud Browser Option Conflicts with the Claimed Local-Only Security Model

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is extremely broad and matches common requests like buying products, booking travel, or subscribing to services, which increases the chance of over-invocation by an orchestrating agent. In a payment-capable skill, over-broad routing is dangerous because accidental invocation can escalate ordinary shopping discussion into real-world purchase actions and expose users to unauthorized spending workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill instructs users to run npx agentpay without pinning an exact package version, which allows the fetched code to change over time and exposes users to supply-chain compromise if the npm package is hijacked or a malicious version is published. In this skill, the risk is amplified because the tool handles purchasing workflows, local encrypted credentials, and browser-driven checkout, so executing an unexpected version could lead to unauthorized purchases or local data access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This unpinned npx agentpay command performs budget configuration but still relies on downloading/executing whatever version npm resolves at the time. Because the package is security-sensitive and connected to payment authorization logic, a compromised release could alter limits, exfiltrate local secrets, or misrepresent transaction controls.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The purchase proposal flow uses npx agentpay buy without version pinning, creating a supply-chain execution point in a payment context. If an attacker controls the published package or a dependency, they could modify the approval workflow, tamper with purchase details, or execute arbitrary code on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

Listing pending purchases via an unpinned npx invocation is still unsafe because it executes package code before showing status. Even seemingly read-only commands can be abused by a malicious package version to run arbitrary local actions or harvest environment data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Approval of a transaction through an unpinned npx agentpay approve command is especially dangerous because it sits directly on the authorization path for purchases. A malicious or swapped package version could approve the wrong transaction, alter checkout behavior, or perform unauthorized actions while appearing legitimate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

npx agentpay status is unpinned and therefore remains a supply-chain execution risk despite being framed as a diagnostic command. In this skill, status commands may expose transaction metadata and run in an environment with access to local wallet state, increasing the consequences of arbitrary code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The history command is also invoked through unpinned npx, enabling arbitrary code execution from a mutable package source. Since transaction history may reveal merchant behavior, amounts, and operational context, a compromised package could leak sensitive financial metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README advertises an HTTP MCP server mode but provides no warning about bind scope, authentication, network reachability, or the sensitivity of exposed purchase operations. Because this skill can initiate or manage real transactions, exposing MCP over HTTP without strong defaults and user-facing warnings could allow other local or remote processes to invoke payment-related tools or harvest transactional data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Launching the MCP server with npx agentpay mcp without version pinning is a significant risk because it exposes tool operations that can initiate or manage purchases. A malicious package version could register backdoored tools, alter tool semantics, or abuse the agent integration boundary for unauthorized actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The HTTP-mode MCP server command is both unpinned and network-exposed, combining supply-chain risk with remote accessibility concerns. If a malicious version is fetched, it could intentionally open unsafe endpoints, weaken authentication assumptions, or expose purchase-related capabilities over the network.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The quick-action buy example repeats the unpinned npx pattern in a highly likely copy-paste path for users. Because this is a purchase-initiating command, a compromised package version could directly manipulate transaction creation or execute arbitrary code under the guise of normal checkout automation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The pending command in the quick-actions table is another executable example that relies on mutable package resolution. Repetition across documentation increases the chance that users normalize insecure invocation patterns and repeatedly execute unverified code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

Budget inspection through an unpinned package still creates a code execution opportunity from a non-immutable source. Given the financial nature of the skill, a malicious package could misreport limits or alter local state to facilitate overspending or conceal abuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The transaction history quick action executes unpinned package code in a context containing financial metadata. Although the command appears informational, a compromised package could leak history contents or stage further attacks on the local machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

Opening the dashboard via unpinned npx agentpay dashboard creates another supply-chain execution point, potentially giving malicious code a path into browser-based flows and transaction interfaces. In a purchasing skill, any UI-launching command can become a vehicle for phishing, tampering, or local compromise if the package source is not fixed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The troubleshooting guidance tells users to run npx agentpay status after checkout failures, again without a fixed version. This is risky because users are especially likely to trust and execute support commands during incidents, giving a compromised package an opportunity to exploit a high-trust moment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup command explicitly handles payment credentials and creates an encrypted local vault, but the reference omits a prominent warning about the sensitivity of the information being entered and stored. In a payment-focused skill, this can mislead users into entering financial credentials without understanding local storage and trust implications, increasing the risk of unsafe use on shared or compromised systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The approve command description says it triggers headless browser checkout, but the CLI reference does not present this as a strong execution warning despite it causing a real purchase to be completed. In the context of an agent purchasing tool, understated documentation can cause accidental approvals or underestimation of the consequences of running the command.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.