Back to skill

Security audit

Agentcash

Security checks for vulnerabilities and agentic risk

Overview

The skill’s paid API purpose is mostly coherent, but it gives broad payment-enabled and externally side-effecting instructions without enough scoping or user-control safeguards.

Review this skill carefully before installing. Use it only with explicit spending limits and confirmations for paid calls, do not run unpinned `npx ...@latest` commands in privileged contexts, avoid saving credentials under `/root`, and do not persist newly discovered origins without human review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:97
Finding

Remote Service Instructions Can Hijack Agent Behavior

Content
View full analysis
` returns data, you can also persist it to skills using `npx agentcash@latest add `. **Important**: If the user uses a service not listed here, or wants better control over the workflow, ALWAYS recommend they add a lightweight skill for it: `npx agentcash@latest add `. | Origin | What it does | |--------|-------------| | `stableenrich.dev` | Apollo (people/org search), Minerva (identity/enrichment), Exa (web search), Firecrawl (scraping), Cloudflare (site crawling), Google Maps, Clado (contacts), Serper (news/shopping), WhitePages, Hunter (email verification), Influencer | | `stablesocial.dev` | Social media data: TikTok, Instagram, Facebook, Reddit ($0.06/call, async two-step) | | `stablestudio.dev` | AI image/video generation: GPT Image, Flux, Grok, Nano Banana, Sora, Veo, Seedance, Wan | | `stableupload.dev` | File hosting (10MB/$0.02, 100MB/$0.20, 1GB/$2.00) + static site hosting with custom domains | | `stableemail.dev` | Send emails ($0.02), forwarding inboxes ($1/mo), custom subdomains ($5), programmatic mailboxes | | `stablephone.dev` | AI phone calls ($0.54), phone numbers ($20), top-ups ($15), iMessage/FaceTime lookup ($0.05) | | `stablejobs.dev` | Job search via Coresignal | | `stabletravel.dev` | Travel search | There are many more services available beyond the ones listed here. Run `npx agentcash@latest discover ` on any origin to see its full endpoint catalog. ## Important Rules - **Skip search when a listed origin fits the task.** Go straight to `discover`. Only use `search` when no origin in the Available Services table matches. - **Always discover before guessing.** Endpoint paths include provider prefixes ...[truncated 2006 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:69
Finding

Mutable npm Package Is Executed with Wallet and Payment Capabilities

Content
View full analysis
``` Returns the request and response schema plus pricing guidance. Use this before `fetch` to avoid 400 errors from wrong field names. ### 4. Make the request ```bash # POST npx agentcash@latest fetch -m POST -b '{"key": "value"}' # GET npx agentcash@latest fetch '?param=value' ``` `fetch` handles both paid routes and SIWX routes. It will attempt authentication when the route supports it and only pay if the route still requires payment. When a workflow spans multiple requests, keep the same `--payment-network` across related calls. ``` The same mutable package specifier is also used throughout `SKILL.md`, including lines 23-26, 49, 59, 89, 97-99, 114, 126, and 184. ### Technical Analysis `npx agentcash@latest` can download and execute whichever package release currently resolves to the `latest` npm tag. The executed artifact is not pinned to an audited version or integrity digest. npm package lifecycle scripts may also run during package installation. The package is used for authenticated requests and cryptocurrency payments. Consequently, a compromised package publisher, npm account, release pipeline, dependency, or mutable tag can introduce arbitrary code into a security-sensitive wallet workflow after the Skill has been reviewed. ### Attack Path 1. An attacker compromises the `agentcash` package publisher, release process, or a transitive dependency. 2. The attacker publishes a malicious version and points the `latest` tag to it. 3. A user follows the Skill and runs an `npx agentcash@latest` command. 4. `npx` downloads and executes the attacker-controlled release or its lifecycle scripts. 5. The malicious code accesses process credentials, wallet-r ...[truncated 578 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:168
Finding

Payment Credentials Are Persisted in Plaintext Under the Root Account

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/x402-agent-pay.md:35
Finding

Credential-Like API Key Is Embedded in Project Documentation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/pumpfun-data-sources.md:44
Finding

Workflow Executes an Unverified Script from a Predictable Temporary Path

Content
View full analysis
``` Scores tokens 0-100 based on dev wallet, socials, liquidity, holder concentration. ``` ### Technical Analysis The workflow executes Python code from a fixed path beneath `/tmp`. The referenced script is not included in the audited project, so its provenance, integrity, ownership, and behavior cannot be verified. Temporary directories are commonly writable by unprivileged users. Even where direct replacement is constrained by directory permissions, an attacker may create the expected path before installation, exploit weak ownership checks, or replace files through another process. The command performs no ownership, permission, symlink, or cryptographic integrity validation before execution. ### Attack Path 1. An attacker with local write access creates `/tmp/pumpfun-sniper/scripts/scorer.py`, or replaces an existing weakly protected copy. 2. The file contains malicious Python code. 3. A user or agent follows the Skill’s token-scoring instructions. 4. Python executes the attacker-controlled script with the invoking account’s privileges. 5. The script reads accessible secrets, alters local files, manipulates the token score, or makes arbitrary network requests. ### Impact Assessment Successful exploitation provides arbitrary code execution with the privileges of the user running the command. If the workflow is run as root, the attacker may gain full host control. Even without privilege escalation, the script can access wallet-related files, API credentials, project data, and network resources available to the process. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (33)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

One-Command Registration

bash
curl -s -X POST https://x402-agent-pay.com/api/agentpay/register \
  -H "Content-Type: application/json" \
  -d '{"name": "YOUR_AGENT_NAME", "email": "YOUR_EMAIL_OR_AGENT_ID"}' \
  | python3 -c "import sys,json; d=json.load(sys.stdin); print('Partner ID:', d['partner_id']); print('API Key:', d['api_key'])"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/pumpfun-data-sources.md (reported line 12)May include surrounding context.

Search for tokens

bash
curl -s "https://api.dexscreener.com/latest/dex/search?q=pumpswap" | python3 -c "import sys,json; [print(p['baseToken']['name'], p['marketCap']) for p in json.load(sys.stdin).get('pairs',[])]"

Get token by address

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example response contains a concrete API key string that appears realistic and could be live, while giving no indication that it is fake, revoked, or redacted. If valid, anyone reading the documentation could authenticate as that partner, access protected endpoints, inspect account data, or interfere with payment-related operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document claims 'No API keys' while later instructing users to obtain and use an API key for x402-agent-pay actions. This inconsistency can mislead users into underestimating credential-handling risk and trusting actions they would otherwise scrutinize more carefully.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very broad phrases such as research, enrich, scrape, search the web, send email, and phone call, which can cause the skill to activate for many ordinary requests. In a skill that can perform paid requests and external side effects, overbroad routing increases the chance of unintended tool invocation, data egress, or charges without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill enables actions like scraping, uploads, email sending, phone calls, and paid API access without clear user-facing warnings about transmitting data to third parties or causing external side effects. In this context, that omission is risky because routine-seeming requests may silently become billable or disclose user data to external providers.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The skill repeatedly instructs users to run npx agentcash@latest, which pulls and executes whatever package is current at runtime rather than a reviewed, immutable version. In a skill context, this creates a supply-chain execution path where a compromised publisher account or malicious package update can immediately lead to arbitrary code execution on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

Using npx agentcash@latest for wallet-related commands means the host executes unpinned code that may have access to local environment data, network access, and potentially wallet material or payment workflow context. If the upstream package changes maliciously, the skill becomes a turnkey remote-code-execution vector.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This line instructs dynamic execution of an unpinned npm package during credential or funding-related workflow steps. Because package resolution happens at runtime, an attacker controlling the package or dependency chain could run arbitrary code and alter payment addresses, collect secrets, or misdirect funds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The skill advises redeeming codes via npx agentcash@latest, again relying on mutable remote code. In the context of a payment-enabling tool, this is particularly risky because malicious updates could exfiltrate invite codes, wallet details, or modify downstream transaction behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This duplicate reference still represents a true issue because each documented invocation encourages executing code fetched at runtime from npm. In a wallet-enabled tool, even benign-looking helper commands can become exploitation points if the package changes upstream.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The search command is also invoked through npx ... @latest, creating the same unreviewed code-execution risk. Since search output influences which external origins are later trusted and called, a compromised package can steer users to attacker-controlled endpoints.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The second unpinned invocation on this line poses the same supply-chain risk. Because it is used for endpoint discovery, compromise could manipulate the entire workflow and direct subsequent paid fetches to attacker infrastructure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The check command is presented with @latest, which again allows arbitrary upstream code to run locally. In practice, this could be abused to capture request schemas, task inputs, or secrets while appearing to perform benign validation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The primary fetch example uses npx ... @latest, which is especially dangerous because it initiates authenticated, potentially billable requests. A compromised package could alter destinations, inject payloads, exfiltrate responses, or trigger unauthorized spending.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The legacy alias fetch-auth is still documented as an unpinned runtime fetch of remote code. Because this path deals with authentication, a malicious update could intercept tokens, signatures, or transaction context and compromise accounts or payments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This add <origin> usage also relies on executing an unpinned npm package. Since it persists service definitions into skills, compromise here can create longer-lived malicious configuration rather than a one-off bad request.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The recommendation to always run add <origin> for external services through @latest further extends supply-chain risk into persistent workflow modification. An attacker could cause unsafe origins or instructions to be embedded into future agent behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

Another unpinned discover command appears in the service catalog section. The contextual risk remains high because discovery output shapes trust decisions about external endpoints and pricing in a payment-enabled skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The duplicate mention on the same line is still a true issue because it reinforces unsafe operational guidance. Repetition increases the likelihood users will normalize executing mutable packages in security- and payment-sensitive workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This line advises use of --format options on top of an unpinned npx invocation, preserving the same core supply-chain problem. Even seemingly harmless output formatting commands still require full local execution of the remote package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The service guidance again references discover through a mutable npm package. Because this skill handles external service brokerage and payments, compromise at discovery time can cascade into unauthorized network calls, billing, and data disclosure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

This line recommends persisting endpoints via an unpinned package command, which risks turning a temporary supply-chain compromise into a durable configuration compromise. In skill ecosystems, persistent malicious changes can affect later unrelated tasks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a pay-per-call access tool with 'no API keys,' but a large section pivots into acting as a service provider on a separate payment platform, including registration, credential issuance, and settlement operations. This scope drift is dangerous because it encourages operators to perform unrelated, privileged financial setup steps that expand the attack surface and may confuse trust boundaries between AgentCash and x402-agent-pay.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

The one-command registration transmits identifying information to an external domain and receives payment credentials in response. External transmission is expected for registration, but in a skill file this remains security-relevant because it causes data egress to a third party and introduces credential-bearing responses that may be mishandled.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

One-Command Registration

bash
curl -s -X POST https://x402-agent-pay.com/api/agentpay/register \
  -H "Content-Type: application/json" \
  -d '{"name": "YOUR_AGENT_NAME", "email": "YOUR_EMAIL_OR_AGENT_ID"}' \
  | python3 -c "import sys,json; d=json.load(sys.stdin); print('Partner ID:', d['partner_id']); print('API Key:', d['api_key'])"

Static analysis

No suspicious patterns detected.