Back to skill

Security audit

Paegents

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Paegents payment and escrow integration skill with real financial and credential risk, but the inspected artifacts are coherent with that purpose and do not show hidden or malicious behavior.

Install only if you intend to let an agent help manage Paegents payment, escrow, service, and related integration workflows. Use scoped API keys, verify `PAEGENTS_API_URL` before running authenticated calls, keep wallet private keys outside chat and outside broad process access, pin SDK versions for production, and require human review before actions that create agreements, sign permits, activate escrow, settle funds, deactivate services, create webhooks, send invites, or handle shipping addresses.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
references/QUICK_START.md:30
Finding

Unpinned Paegents SDK Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: references/QUICK_START.md:30-35
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

bash
# Python
pip install paegents

# OR TypeScript
npm install paegents

Technical Analysis

Both installation commands resolve the latest package version available at installation time. They do not specify an exact version, verify an integrity hash, use a lockfile, or otherwise ensure that the installed package is the version reviewed alongside this Skill.

The effective implementation can therefore change independently of the audited Skill. Package installation or runtime hooks introduced by a compromised future release could execute with the privileges of the user running the installation. This is particularly sensitive because the SDK operates in a context containing Paegents API credentials and potentially wallet-signing material.

This finding does not establish that the current paegents packages are malicious. The vulnerability is the absence of controls that bind installation to a reviewed artifact.

Attack Path

  1. An attacker compromises the package publisher, package registry account, or a transitive dependency.
  2. The attacker publishes a malicious version under the legitimate paegents package name.
  3. A user follows the documented unpinned pip install paegents or npm install paegents command.
  4. The package manager resolves and installs the malicious release.
  5. Malicious installation hooks or runtime code execute in the user's environment.
  6. The code may read accessible environment variables, alter transaction parameters, intercept locally generated signatures, or perform other actions allowed by the user's process privileges.

Impact Assessment

Successful exploitation could provide code execution with the privileges of the user installing or running the SDK. Depending on the host configuration, exposed ...[truncated 589 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the SDK to an exact reviewed version consistent with the Skill release, for example:
    bash
    pip install paegents==2.9.1
    npm install paegents@2.9.1 --save-exact
    
  2. Supply Python requirements with hashes and use pip install --require-hashes.
  3. Commit npm lockfiles and use npm ci rather than unconstrained installation in automated environments.
  4. Verify package provenance, checksums, and publisher identity before installation.
  5. Run the SDK in an isolated environment with only the minimum required credentials and filesystem access.
  6. Require an explicit security review before updating the pinned SDK or its transitive dependencies.

T09 · Insecure Skill Coding Practices

Warning
Location
references/QUICK_START.md:43
Finding

Environment-Controlled API URL Can Redirect the Paegents API Key

Content
View full analysis

Vulnerability Details

File Location: references/QUICK_START.md:43-63
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Additional relevant locations include SKILL.md:24-28, references/API_REFERENCE.md:5, and assets/openapi-subset.json:8-10.

Vulnerable Code

bash
export PAEGENTS_API_URL=https://app.paegents.com/api
export PAEGENTS_API_KEY=sk_your_key
export PAEGENTS_AGENT_ID=your_agent_id
# Buyer wallet credentials (address + signing key) are managed separately.
# See your wallet provider or keystore for secure key management.
python
import os
from paegents import PaegentsSDK, ServiceRegistration

sdk = PaegentsSDK(
    api_url=os.environ["PAEGENTS_API_URL"],
    agent_id=os.environ["PAEGENTS_AGENT_ID"],
    api_key=os.environ["PAEGENTS_API_KEY"],
)

The API reference explains how that credential is transmitted:

markdown
Authenticated agent endpoints use `X-API-Key: sk_...` unless noted otherwise.

The machine-readable API definition also advertises a plaintext development endpoint:

json
"servers": [
  {"url": "http://localhost:8000", "description": "Local development"},
  {"url": "https://app.paegents.com/api", "description": "Production"}
],

Technical Analysis

The API destination and credential are both read from environment variables and passed directly to the SDK. The documentation recommends the legitimate production URL, but it does not require HTTPS, validate the destination host, distinguish production credentials from development credentials, or require operator confirmation before authenticated financial operations.

If PAEGENTS_API_URL is modified through environment poisoning, an unsafe deployment configuration, a compromised shell profile, or automation secrets, the SDK may send the X-API-Key header to an unintended endpoint. A plaintext HTTP destination can additionally expose requests ...[truncated 1770 chars]

Remediation
View remediation

Remediation Suggestions

  1. Default to https://app.paegents.com/api and validate the destination before constructing an authenticated client.
  2. Require HTTPS for all non-local authenticated connections.
  3. Allowlist approved production and development hostnames rather than accepting arbitrary destinations.
  4. Reject URLs containing unexpected credentials, redirects, nonstandard schemes, or unapproved hosts.
  5. Use separate, limited-scope credentials for local development, staging, and production.
  6. Never permit production API keys to be used with the documented plaintext localhost server.
  7. Display the resolved destination and require operator confirmation before payment, activation, or settlement operations when a nondefault endpoint is configured.
  8. Ensure the SDK does not forward authentication headers across cross-origin redirects.
  9. Add explicit documentation warning that PAEGENTS_API_URL determines where the API key is transmitted.
  10. Support short-lived, revocable, and operation-scoped credentials where the platform permits them.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
e to register services,
  create usage agreements, activate bilateral escrow, route metered usage, and
  settle with the recommended execution mode.
license: MIT
compatibility:
  - claude-code
  - openclaw
  - cursor
metadata:
  version: "2.9.1"
  author: paegents
  homepage: https://paegents.com
  repository: https://github.com/MarkMcDaniels/paegents-pay-skill
  payment_rail: stablecoin
  escrow_model: bilateral
  networks: base,base-sepolia
  asset: USDC
  beta: true
  openclaw:
    requires:
      env:
        - PAEGENTS_API_URL
        - PAEGENTS_API_KEY
        - PAEGENTS_AGENT_ID
    primaryEnv: PAEGENTS_API_KEY
allowed-tools: Read Write Edit WebFetch
---

# Paegents Pay

Use this skill when an agent needs to buy or sell a service through Paegents without bypassing the public product surface.

Keep the guidance at the integration layer. Do not expose private keys, seller-side secrets, unpublished endpoints, internal architecture, or internal operations detail. Explain what the sy

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
90% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
## Do Not Use This When

- the task is asking for internal implementation details rather than product usage
- someone wants to bypass policy, approval, verification, or signing requirements
- someone wants to share or log private keys, raw wallet secrets, or seller credentials
- a one-off direct payment is being confused with a bilateral escrow agreement

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/API_REFERENCE.md (reported line 29)May include surrounding context.

md
### PUT /agents/services/{service_id}
Update service config.

### DELETE /agents/services/{service_id}
Deactivate a service.

### GET /agents/services/{service_id}

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/API_REFERENCE.md (reported line 143)May include surrounding context.

md
### GET /agents/{agent_id}/webhooks
List webhook subscriptions.

### DELETE /agents/{agent_id}/webhooks/{subscription_id}
Delete a webhook subscription.

Advanced webhook management may exist in the SDK or dashboard, but it is intentionally omitted from this public reference.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
- the signer has gas if the chosen settlement mode requires direct broadcast
- the SDK is installed when SDK use is expected

Do not ask users to paste secrets into chat. Assume secrets stay in their environment.

## Operating Rules

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The API subset includes destructive and state-changing operations such as update and delete service actions without any documented confirmation, approval, or warning expectations at the skill level. In an agent context, that omission can cause accidental irreversible changes, especially when autonomous planners may treat these endpoints as routine tools and execute them without user awareness.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API exposes shipping-address, delivery-status, and tracking operations for physical goods despite the skill being described as a payments/escrow integration. That mismatch is dangerous because it introduces PII handling and real-world fulfillment workflows that users and higher-level policy controls may not expect, increasing privacy and operational risk if an agent collects or updates shipping data under a narrower payment-oriented trust model.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented API surface includes webhook subscription management and invite issuance flows that extend beyond the stated payment/escrow-focused skill purpose. This scope expansion increases the chance an agent or user invokes account-growth, notification, or integration features without expecting those capabilities, which can lead to unintended external data egress, trust-boundary expansion, or unauthorized onboarding actions if the surrounding skill UX does not clearly constrain them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The quick start examples show users supplying both the platform API key and a service-side API key to SDK registration flows without clearly warning that these secrets are transmitted to the Paegents platform/API. In an agent-execution context, operators may paste production credentials into automation assuming they remain local, which increases the risk of unintended credential disclosure, over-privileged integration, or later compromise if the platform, logs, or downstream handling are misconfigured.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
0% confidence
Finding

No natural-language policy violations were identified in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Listing agent events and acknowledging them are auxiliary platform operations that are not mentioned in the manifest’s narrower description of payment, escrow, and metered-usage actions. While potentially useful, they extend the skill’s behavior into event-consumption workflow management beyond the declared purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown API reference tells readers to use an X-API-Key: sk_... header but does not include any warning not to expose, log, or share API keys. Because markdown files should warn about behaviors affecting privacy or system integrity, mentioning live credential use without a basic handling warning is a minor missing-disclosure issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.