Back to skill

Security audit

crypto-payroll

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent about crypto payroll, but it also includes paid non-payroll gateway actions that conflict with its stated scope and deserve review before use.

Review this skill carefully before installing. Its main payroll flow has sensible safeguards, but users should limit it to explicit USDC payroll runs and avoid using the optional related gateway calls from this skill unless those workflows have their own approval, validation, and signing controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises optional token lookup and standalone estimate operations even though the manifest explicitly says not to use the skill for token lookups or standalone cost estimates. This contradiction weakens policy enforcement and can cause an agent to perform paid external calls outside the user's authorized payroll-execution intent, potentially leaking metadata and incurring charges.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill materially broadens its operational scope beyond payroll into tax, invoicing, escrow, and general batch-payment actions. That creates scope confusion and increases the chance an agent will invoke this skill for adjacent money-moving workflows that were not subject to the same constraints, approvals, or validation logic, leading to unauthorized data disclosure or unintended financial actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.