Back to skill

Security audit

nansen-alerts-webhook-listener

Security checks for vulnerabilities and agentic risk

Overview

This skill openly sets up a local Nansen alert webhook listener with a public tunnel and reasonable safeguards, with one supply-chain caveat around optional unpinned localtunnel use.

Install only if you are comfortable running a local webhook server and exposing it through ngrok or localtunnel. Prefer ngrok or a pinned/preinstalled tunnel tool, keep the webhook secret private, and stop the server and tunnel when finished.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
| | **ngrok** (recommended) | **localtunnel** |
|---|---|---|
| Stability | Stable — persistent connections with keepalive | Flaky — free relay drops idle connections without warning, tunnels die randomly |
| Install | `brew install ngrok` + free account at ngrok.com | Zero install (`npx localtunnel`) |
| HTTPS | Yes | Yes |
| Auth required | Yes (free authtoken from ngrok.com) | No |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

text
Get the public URL from ngrok's output or its local API:
```bash
curl -s http://127.0.0.1:4040/api/tunnels | node -e "process.stdin.on('data',d=>console.log(JSON.parse(d).tunnels[0]?.public_url))"

The webhook URL is https://<subdomain>.ngrok-free.dev/webhook.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs use of npx localtunnel without pinning a version, so each execution may fetch and run the latest package from the registry. This creates a supply-chain risk: a compromised or malicious package update could execute arbitrary code on the user's machine in a workflow that already exposes a public tunnel.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This is a second instance of the same issue: npx localtunnel --port 9477 will resolve and execute whatever package version is current at runtime. In a security-sensitive skill that handles webhook exposure, unpinned remote package execution meaningfully increases supply-chain attack surface.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The summary section repeats the unpinned npx localtunnel invocation, reinforcing a pattern of executing an unreviewed latest package from npm. Repetition increases the likelihood that users will follow the unsafe path, so this remains a real supply-chain vulnerability.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.