Back to skill

Security audit

livecheck

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to provide the advertised paid URL-checking service, but it should be reviewed because it repeatedly asks users to run an unpinned remote CLI in wallet and paid-service workflows.

Review before installing. Use only for specific URLs you intend to check, avoid sending private order or tokenized URLs unless necessary, protect webhook secrets and owner tokens, and prefer a pinned reviewed `agentcash` version instead of `@latest` before using wallet or paid endpoint commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The manifest itself advertises use of npx agentcash@latest, embedding the unsafe execution model into the skill's top-level interface. Because manifests are often parsed or surfaced automatically, this increases systemic risk by propagating an unpinned supply-chain dependency across integrations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad everyday language such as 'before I buy' or 'tell me when', which can cause the skill to activate in contexts beyond its intended scope. Over-broad triggering is dangerous because it may route unrelated user requests into a networked, paid, and potentially sensitive capability without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill instructs users to run npx agentcash@latest, which fetches and executes whatever package version is current at runtime rather than a reviewed, immutable version. This creates a supply-chain risk: a compromised upstream package, account takeover, or malicious update could cause arbitrary code execution in the user's environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a live availability checker for listings, products, and jobs, but it also exposes form-submission and order-confirmation functions. This scope expansion can mislead operators and agents into using the skill in higher-sensitivity workflows involving transactional or personal data that were not clearly disclosed in the skill's stated purpose.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This invocation again relies on npx ...@latest, so the actual code executed is not stable or auditable from the skill text alone. In an agent skill context, encouraging repeated use of floating executable dependencies increases the chance of silent compromise through package tampering or malicious releases.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill tells operators to run a schema-discovery command via an unpinned package version, which could execute attacker-controlled code if the package supply chain is compromised. Because this is a prerequisite step before any endpoint usage, it broadens exposure and normalizes unsafe execution habits.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This example uses the same floating @latest package reference for the check endpoint, preserving the same arbitrary code execution and supply-chain exposure. Repetition across multiple examples increases the likelihood that users will copy and run the unsafe pattern.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The watch workflow includes an unpinned executable package invocation, which is particularly sensitive because it sets up long-lived monitoring and callback configuration. A malicious package version could exfiltrate webhook secrets, URLs, or other operator data during setup.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Form and order confirmation operate on thank-you pages and order-status URLs, which can contain references, identifiers, or other sensitive transactional context, yet these features are not justified by the core 'live page availability' purpose. That mismatch increases the risk of over-collection, accidental data exposure, and misuse in contexts requiring stronger controls than simple availability checks.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The confirm example executes an unpinned package version while handling confirmation URLs that may include sensitive references or tokens. If the package is compromised, those URLs and associated metadata could be harvested or abused.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This order-confirmation example repeats the same unpinned package execution pattern in a context that may involve order identifiers or customer transaction metadata. The combination of remote code execution risk and potentially sensitive commerce data makes the pattern materially dangerous.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The workflow example for verifying merchant URLs again uses a floating executable dependency. Even though the command appears simple, it still permits arbitrary code execution from the package registry and should be treated as a supply-chain vulnerability.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The documentation instructs users to run npx agentcash@latest balance, which fetches and executes the latest published package version at runtime. Using @latest is effectively unpinned and creates a supply-chain risk: if the package or publisher is compromised, users may execute malicious code without any review. In a payment-related skill that handles wallet operations, this raises the stakes because compromise could expose funds or credentials.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command npx agentcash@latest redeem YOUR_CODE executes whatever version is currently published as latest, making the setup flow vulnerable to malicious package updates or account takeover of the package publisher. Because this step interacts with wallet funding or redemption, exploitation could directly lead to theft of funds, secrets, or account manipulation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The guidance to run npx agentcash@latest accounts again relies on executing an unpinned remote package at runtime. Since this command reveals deposit links and wallet addresses, a compromised package could misdirect deposits, exfiltrate wallet metadata, or present attacker-controlled payment details.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The command npx agentcash@latest check https://livecheck.fly.dev/v1/verify causes users to execute the newest package version when validating the service schema. Even though the purpose is benign, runtime execution of an unpinned CLI remains a supply-chain exposure, and the skill context increases concern because the tool is tied to paid API interactions and wallet settlement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.