Back to skill

Security audit

Acp Job Submitter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Review case because it directs paid crypto-related job submission to external agents with broad scope and weak user-safety guidance, though I found no evidence of deception or malware.

Install only if you are comfortable with an agent submitting paid crypto-related jobs to external ACP agents. Review every agent address, service, price, job requirements, and wallet action before approval; do not include private keys, seed phrases, credentials, proprietary strategies, or sensitive account data in job payloads. Avoid running the shown `npx tsx` commands unless the implementation and dependencies are present, pinned, and reviewed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:82
Finding

Unpinned npm Package Execution via npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 82–88
Vulnerability Type: Supply-chain risk caused by unpinned, on-demand npm package execution
Risk Level: Medium

Vulnerable Code:

javascript
// Submit trending tokens job
await exec("npx tsx bin/acp.ts job create 0xe5B38F112b92Ce8F2103eDAbA7E9a9842f12d5f6 trending_tokens --requirements '{\"initiate_trending_altcoins_job\":true}'")

// Check job status  
await exec("npx tsx bin/acp.ts job status 123456789")

// Browse agents
await exec("npx tsx bin/acp.ts browse trading")

Technical Analysis

The documented commands execute npx tsx without specifying an exact package version. If tsx is unavailable locally, npx may download and execute a package resolved from the configured npm registry. The artifact provides no package.json, lockfile, integrity metadata, or trusted-registry configuration to constrain that resolution.

As a result, the code ultimately executed can change after the Skill has been reviewed. Registry compromise, dependency-account compromise, or manipulated package resolution could cause attacker-controlled package code to run with the invoking process's permissions.

The referenced local entry point, bin/acp.ts, is also absent from the supplied artifact, which contains only SKILL.md. Therefore, the advertised implementation cannot be audited or verified, and the examples do not operate as provided. This absence does not itself establish malicious behavior, but it prevents validation of the claimed paid-job and cryptocurrency operations.

Attack Path

  1. An Agent or user follows one of the documented command examples.
  2. The system invokes npx tsx without a pinned version.
  3. If no trusted local installation is available, npx resolves the package through the configured npm registry.
  4. A compromised registry package, maintainer account, or package-resolution environment supplies attacker-controlled code ...[truncated 962 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add the referenced bin/acp.ts implementation to the package and subject it to security review.
  2. Declare tsx at an exact reviewed version in package.json and commit the corresponding lockfile.
  3. Install dependencies in a controlled build step using lockfile enforcement, such as npm ci, rather than permitting on-demand package retrieval during Skill execution.
  4. Invoke the locally installed, pinned executable, such as ./node_modules/.bin/tsx, and disable automatic remote installation.
  5. Enforce an approved npm registry and verify package integrity and provenance.
  6. Run the command with least privilege in a sandbox that restricts filesystem, environment-variable, credential, and network access.
  7. Require explicit user confirmation before submitting paid jobs, initiating trades, swaps, or performing any wallet-authorized operation.
  8. Validate agent addresses, service names, requirements, prices, and transaction details before requesting signatures or transferring funds.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill promotes submitting user jobs and requirements to external ACP agents but does not warn that prompts, queries, and structured requirements may be transmitted to third parties. In this context, users may unknowingly send sensitive trading intent, wallet-related information, or proprietary strategies to external agents, creating confidentiality and privacy risks.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs use of npx tsx without pinning an exact package version, which allows execution to vary over time and can expose users to a compromised or unexpected package release. Because these commands are presented as operational examples for job submission, an attacker controlling the dependency supply chain could achieve arbitrary code execution in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The npx tsx command is unpinned, so the code executed depends on whatever version the package registry serves at runtime. In a skill that encourages shell execution for operational workflows, this creates a supply-chain risk that could lead to arbitrary code execution if the package or dependency chain is hijacked.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx tsx without version pinning makes the browsing command depend on mutable upstream package state. Even though this example is for browsing agents rather than submitting a trade, compromise of the executed package could still run arbitrary code on the host system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation includes shell execution examples for creating jobs, checking status, and browsing agents, but it does not warn users that these are local command executions with associated system and dependency risks. In a crypto/trading automation context, normalizing direct shell commands without caution increases the chance of unsafe copy-paste execution and reduces informed consent around local execution risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.