Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md scripts/run-test.sh mainnet-beta
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent payment-test helper that discloses its external service use and real-money mainnet cost, with no evidence of hidden persistence, credential theft, or destructive behavior.
Install only if you are comfortable using an external payment-testing service. Prefer devnet for dry runs, confirm before any mainnet wallet payment, avoid putting secrets or private identifiers in the optional label, and treat MPP_BASE_URL as trusted configuration if you override it.
Referenced artifact was not completely inspected
scripts/run-test.sh mainnet-beta
Referenced artifact was not completely inspected
scripts/run-test.sh mainnet-beta
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
esac
echo "Starting $NETWORK MPP test…"
START=$(curl -s -X POST "$BASE/api/mpp/start" \
-H 'Content-Type: application/json' \
-d "{\"network\":\"$NETWORK\",\"label\":\"$LABEL\"}")
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
for i in $(seq 1 120); do
sleep 5
RESP=$(curl -s "$BASE/api/mpp/tests/$REF")
STATUS=$(printf '%s' "$RESP" | python3 -c "import sys,json;print(json.load(sys.stdin).get('status',''))")
case "$STATUS" in
confirmed)
The skill documents shell-based execution paths, including a helper script and curl commands, but does not declare any tool scope or allowed-tools restrictions. That mismatch can cause an agent platform to permit broader execution than intended, increasing the risk of unintended command execution or network access when the skill is invoked.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -s -X POST https://mpptester.com/api/mpp/start \
-H 'Content-Type: application/json' \
-d '{"network":"mainnet-beta"}'
The script transmits user-controlled data (LABEL) and operational metadata (NETWORK) to an external service at mpptester.com, and the destination can be overridden via MPP_BASE_URL. While this is core to the skill's purpose, it still creates a real data exfiltration and trust-boundary risk because users may unknowingly send sensitive labels or interact with an attacker-controlled endpoint if the environment variable is modified.
esac
echo "Starting $NETWORK MPP test…"
START=$(curl -s -X POST "$BASE/api/mpp/start" \
-H 'Content-Type: application/json' \
-d "{\"network\":\"$NETWORK\",\"label\":\"$LABEL\"}")
No suspicious patterns detected.