Back to skill

Security audit

Zetto Network

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for a business marketplace, but it installs an unpinned MCP server with broad messaging, payment, webhook, and account-management powers, so users should review it carefully before installing.

Install only if you are comfortable running Zetto's MCP server from npm and giving it access to any environment variables available to the agent, including `ZETTO_API_KEY`. Prefer a pinned, reviewed server version, use a constrained environment, and require explicit confirmation before payments, escrow release, messages, listing deletion, KB updates, or webhook changes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:7
Finding

Unpinned Third-Party MCP Server Is Automatically Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:7
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: High

Vulnerable Code Snippet:

yaml
metadata: '{"openclaw": {"emoji": "\U0001F91D", "user-invocable": true, "requires": {"bins": ["npx"]}, "install": [{"name": "zetto-mcp", "type": "mcp", "command": "npx", "args": ["-y", "@zetto/mcp-server"]}]}}'

Technical Analysis

The skill configures npx -y @zetto/mcp-server as its MCP server command. No exact package version or integrity value is specified. Consequently, package resolution depends on mutable npm registry state at execution time rather than on a dependency version that was reviewed with this skill.

The -y option suppresses the normal installation confirmation, allowing the resolved package to be downloaded and executed automatically. The source code of @zetto/mcp-server is not included in the audited project, so its implementation and effective behavior cannot be verified from this repository.

This is particularly sensitive because the documented MCP capabilities include messaging, payments, escrow operations, knowledge-base management, and webhook configuration. A compromised or unexpectedly modified package release could operate inside the agent process with the permissions and credentials available to that process.

Attack Path

  1. An attacker compromises the npm account, publication pipeline, or distribution path for @zetto/mcp-server, or causes an unsafe release to become the version selected by npm.
  2. A user installs or invokes the Zetto skill.
  3. The skill executes npx -y @zetto/mcp-server.
  4. npx resolves and downloads the mutable package release without asking the user for confirmation.
  5. The downloaded package executes locally under the account running the agent.
  6. Malicious package code can access process-level resources available to it and may abuse configured credentials or exposed MCP ...[truncated 759 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin @zetto/mcp-server to a reviewed exact version, for example @zetto/mcp-server@1.2.3, rather than relying on npm's current resolution.
  2. Remove automatic -y execution where practical so installation is an explicit, reviewable operation.
  3. Commit lockfile and package-integrity metadata in the component responsible for installation.
  4. Verify package provenance using npm provenance attestations, trusted publishers, signatures, or an equivalent controlled artifact-verification process.
  5. Publish or vendor the relevant MCP server source so its implementation can be reviewed alongside the skill.
  6. Run the MCP server in a sandbox with minimal filesystem, network, environment-variable, and operating-system permissions.
  7. Provide sensitive credentials only when required and ensure payment, messaging, webhook, and destructive operations remain subject to explicit authorization checks outside the potentially mutable dependency.
  8. Establish dependency monitoring and a controlled update process that reviews each new package version before deployment.

T08 · Insecure Dependencies

Error
Location
README.md:6
Finding

Installation Documentation Executes a Mutable Latest Installer Release

Content
View full analysis

Vulnerability Details

File Location: README.md:6
Vulnerability Type: Unpinned installation-time dependency
Risk Level: High

Vulnerable Code Snippet:

bash
npx clawhub@latest install zetto-network

Technical Analysis

The documented installation command explicitly instructs users to execute clawhub@latest through npx. The latest distribution tag is mutable and can point to a different package version after this skill has been reviewed. Therefore, the code executed during installation is not cryptographically or semantically bound to the audited project version.

Although no malicious installer behavior was present in the reviewed repository, this pattern creates a supply-chain trust boundary at installation time. A compromised npm publication account, malicious newly published release, or compromised package distribution channel could replace the effective installer logic without requiring any modification to this repository.

Attack Path

  1. An attacker compromises the npm package or release process associated with clawhub, or causes the mutable latest tag to reference a malicious release.
  2. A user follows the project's installation instructions and runs npx clawhub@latest install zetto-network.
  3. npm resolves latest to the attacker-controlled release and downloads it.
  4. npx executes that release locally as part of the installation process.
  5. The malicious installer runs with the user's current process permissions and can tamper with the installed skill or access resources available to that user.

Impact Assessment

Exploitation can result in arbitrary code execution with the privileges of the user running the installation command. Potential consequences include theft of accessible credentials, modification of local agent configuration, installation of a tampered skill, filesystem changes, or execution of additional payloads.

The exact impact depends on the invoki ...[truncated 288 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace clawhub@latest with a reviewed exact version, such as clawhub@X.Y.Z.
  2. Publish the expected package integrity digest and provide a documented verification procedure.
  3. Use npm provenance attestations, trusted publishing, and protected release workflows.
  4. Advise users to perform installation under an unprivileged account in a constrained environment.
  5. Test and review installer upgrades before changing the documented version.
  6. Automate dependency and provenance monitoring while requiring human approval before adopting a new installer release.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (7)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
| Tool | What it does |
|------|-------------|
| `mesh_register` | Claim @handle, create agent profile |
| `mesh_update_profile` | Update skills/pricing via natural language |
| `mesh_get_profile` | View your full profile + settings |
| `mesh_get_trust_score` | Trust score with signal breakdown |
| `mesh_set_visibility` | Toggle listed/stealth mode |

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to run npx clawhub@latest install zetto-network, which fetches and executes the latest package version at install time rather than a pinned, reviewed release. This creates a supply-chain risk: if the package is compromised or a malicious update is published, users may execute untrusted code simply by following the documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises capabilities for conversations, payments, escrow, and knowledge-base operations without warning that these actions may transmit sensitive data to third parties or trigger financial or irreversible state changes. In an agent skill context, this omission is more dangerous because operators may enable the skill expecting simple browsing, while the toolset also supports messaging, data sharing, and payment actions that carry privacy and transaction risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation description includes broad triggers like 'find business partners' and 'connect with other agents', which can overlap with many ordinary networking or business-discovery requests. This can cause the skill to be invoked outside a narrowly intended scope, increasing the chance of unnecessary exposure to marketplace actions or data flows.

Content

No source excerpt is available for this finding.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
84% confidence
Finding

The instruction 'Never tell the user they need an account before showing them the network' is a growth-oriented behavioral steering rule that prioritizes funneling the user through browse mode before disclosing access constraints. While not overtly malicious, it manipulates presentation to influence user behavior and can reduce transparency about prerequisites for transactional features.

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

md
## Rules

- **Always browse first.** Never tell the user they need an account before showing them the network. Let them see the value.
- **Show scores as percentages.** "92% match" not "0.92 score".
- **Confirm before acting.** Always ask before approving matches, declining matches, sending messages, or making payments.
- **Present matches as ranked tables** with handle, name, score, what they offer/seek, trust score.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

md
## Constraints

- **Never fabricate network data.** Only show what the API returns.
- **Never auto-approve matches** without explicit user confirmation.
- **Never send messages** without user confirmation of the content.
- **Never send payments** without explicit user confirmation of amount and recipient.
- **Never expose API keys** in output.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 32)May include surrounding context.

md
## Agent Profiles
Public profile: https://zetto.to/{handle}
Agent card (A2A): https://api.zettoai.com/.well-known/agent.json?handle={handle}
Agent email: {handle}@zetto.to

## Trust Scores

Static analysis

No suspicious patterns detected.