Back to skill

Security audit

stinkyboy-bodega

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent paid remote-tool marketplace, but it needs review because it can create and run new remote tools immediately while using wallet, payment, real-input, and callback data.

Review before installing. Only use this with data and wallet activity you are comfortable sending to the remote service, avoid internal or secret-bearing callback URLs, and require explicit quotes and confirmation before paid or dynamically created tool calls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README explicitly instructs users to send a caller wallet and allows an optional callback_url to a remote third-party MCP service, but it provides no privacy notice, data-handling explanation, retention policy, or warning about the sensitivity of those fields. Wallet addresses are persistent identifiers that can be used to profile spend and activity, and callback URLs can expose internal endpoints, tokens, or network topology if users supply sensitive URLs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill routes user requests to an external MCP endpoint and exposes wallet-linked operations such as payment, quoting, and spend reporting, but it does not clearly warn users that prompts, tool inputs, and wallet identifiers may be transmitted to a third-party service. This is dangerous because users may unknowingly send sensitive business data or financial identifiers off-platform, creating privacy, compliance, and data-handling risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The create_and_call feature can synthesize a new tool from a natural-language outcome and immediately execute it in the same session, but the skill text does not prominently warn users about this dynamic code/tool generation behavior. This is riskier than a normal remote tool call because it combines generation and execution without a clear review step, increasing the chance of unintended external actions, unsafe data handling, SSRF-style callback misuse, or execution of behavior the user did not explicitly inspect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.