Back to skill

Security audit

Agentic Commerce - Buy IRL Items With USDC

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent shopping and crypto-checkout helper, but its bundled signing flows can expose wallet keys and automatically submit irreversible blockchain payments without adequate review.

Review this skill carefully before use. Avoid the --private-key scripts with any valuable wallet; prefer browser or hardware wallet signing, verify recipient/token/amount/fees before approving, and understand that order creation sends your email, shipping details, wallet address, and purchase information to api.purch.xyz.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/buy_and_sign.ts:74
Finding

Blind Signing and Broadcasting of Untrusted Blockchain Transactions

Content
View full analysis
{ const response = await fetch(`${BASE_URL}/buy`, { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify(params), }); if (!response.ok) { const error = await response.text(); throw new Error(`HTTP ${response.status}: ${error}`); } return response.json(); } async function signAndSendTransaction( serializedTx: string, privateKey: string, rpcUrl: string = clusterApiUrl("mainnet-beta") ): Promise<{ success: boolean; signature?: string; explorerUrl?: string; error?: string }> { let keypair: Keypair; try { const keyBytes = bs58.decode(privateKey); keypair = Keypair.fromSecretKey(keyBytes); } catch (e) { return { success: false, error: `Invalid private key: ${e}` }; } let transaction: VersionedTransaction; try { const txBytes = bs58.decode(serializedTx); transaction = VersionedTransaction.deserialize(txBytes); } catch (e) { return { success: false, error: `Invalid transaction: ${e}` }; } try { transaction.sign([keypair]); } catch (e) { return { success: false, error: `Failed to sign: ${e}` }; ...[truncated 4650 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/buy_and_sign.ts:143
Finding

Wallet Private Keys Exposed Through Command-Line Arguments

Content
View full analysis
= {}; let i = 0; while (i < args.length) { const arg = args[i]; if (arg === "--asin" && args[i + 1]) result.asin = args[++i]; else if (arg === "--url" && args[i + 1]) result.url = args[++i]; else if (arg === "--variant" && args[i + 1]) result.variant = args[++i]; else if (arg === "--email" && args[i + 1]) result.email = args[++i]; else if (arg === "--wallet" && args[i + 1] ...[truncated 2716 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/sign_transaction.ts:1
Finding

Unpinned Signing Dependencies and Implicit npx Runtime Retrieval

Content
View full analysis
[rpc_url] */ ``` The runtime imports dependencies in the same process that receives and decodes the private key: ```typescript import { Connection, Keypair, VersionedTransaction, clusterApiUrl, } from "@solana/web3.js"; import bs58 from "bs58"; ``` ### Technical Analysis No project lockfile or version-pinned dependency manifest was present in the supplied directory structure. The installation commands therefore resolve whatever package versions are current at installation time. Because these dependencies execute inside a process that handles wallet private keys, a compromised package release, registry account, transitive dependency, or installation source could access: - `process.argv`, including the private key. - In-memory key bytes and keypair objects. - Serialized and signed transactions. - Network access available to the process. The `#!/usr/bin/env npx ts-node` shebang is especially risky when `ts-node` is not already installed locally. Depending on the `npx` version and configuration, invoking the script may retrieve and execute a package dynamically. T ...[truncated 1586 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The declared description covers a broad shopping API including product search, shopping assistants/recommendations, crypto checkout, and signing/submitting blockchain transactions. This code chunk only handles purchase-order creation for Amazon or Shopify products by ASIN/URL/variant and sends the request to an external API. It explicitly states 'without signing the transaction' and only returns/prints a serialized transaction for a later signing step. Therefore the actual behavior is a narrower subset of the declared functionality, with notable missing declared capabilities—especially search and transaction signing/submission. The checkout/order-creation portion is consistent, but the description does not accurately represent what this specific code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code substantially aligns with part of the declared purpose around crypto checkout and signing/submitting blockchain transactions for purchases. However, it does not implement product search, recommendation, or general shopping-assistant behavior; instead it requires direct product identifiers/URLs and focuses narrowly on order creation plus Solana transaction signing/submission. It also does not support Base chain checkout despite that being declared. These are material differences in capabilities, so the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code aligns with the product-search portion of the description: it accepts natural-language shopping queries, optionally includes price preferences, calls a shopping API endpoint, and formats Amazon/Shopify-like product results. However, the declared purpose also prominently includes crypto checkout, creating purchase orders, and signing/submitting Solana or Base transactions. None of those capabilities appear in this code chunk. There is no wallet handling, blockchain interaction, checkout flow, order creation, or transaction signing/submission logic. Therefore the supplied code only covers a subset of the declared functionality, making the description materially broader than the actual behavior shown.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code only supports shopping search behavior: it parses CLI arguments, optionally builds a price-range context, POSTs the query to https://api.purch.xyz/shop, and displays product results. The returned product structure includes search-related metadata such as title, price, source, ASIN, URL, and variant ID. There is no code for creating orders, initiating checkout, handling USDC on Solana or Base, signing transactions, or submitting blockchain transactions. The Amazon/Shopify product-search portion of the description is consistent, but the broader declared purpose materially overstates the implemented capabilities of this code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

md
bun run scripts/search.ts "wireless headphones" --price-max 100

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

md
bun run scripts/shop.ts "wireless headphones with good noise cancellation"

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script requires a raw private key to be passed on the command line and then uses it to sign and submit a live mainnet transaction. Command-line secrets are commonly exposed through shell history, process listings, audit logs, CI job output, and support transcripts, so this creates a realistic path to wallet compromise and fund theft.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script automatically signs and submits a live Solana transaction returned by a remote API, using a user-supplied private key, without any independent review step, transaction simulation output, amount confirmation, or explicit consent gate immediately before broadcast. In this skill context, that is especially dangerous because the code is designed for real purchases and trusts externally provided serialized transaction data, so a user could unintentionally authorize an unexpected or manipulated on-chain payment.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script accepts a raw private key via CLI, obtains a serialized transaction from a remote API, and immediately signs and broadcasts it without a human confirmation step or a clear irreversible-action warning. This is dangerous because the remote API effectively controls the transaction payload, and users may unknowingly authorize an on-chain transfer that cannot be reversed once submitted.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This CLI instructs users to pass a raw Solana private key as a command-line argument and then signs and broadcasts a transaction from externally supplied serialized bytes. Command-line arguments are commonly exposed through shell history, process listings, logs, CI output, and telemetry, and the script provides no explicit warning or transaction review step despite irreversible on-chain consequences. In the context of a shopping/checkout skill that signs blockchain purchases, this is especially dangerous because users may be conditioned to sign opaque purchase transactions received from an API without independently verifying recipients, amounts, or program instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Accepting a raw private key on the command line exposes secret material through shell history, process listings, terminal logging, CI job logs, and crash telemetry. Because this script is specifically intended to sign real Base/EVM checkout transactions, compromise of the key can lead to full wallet takeover and unauthorized fund transfers far beyond a single purchase.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents extensive network interactions with an external API but does not declare any explicit tool scope or permission boundaries. In agent environments, missing scope declarations can cause users or orchestrators to underestimate that the skill sends data off-platform, increasing the risk of unintended external transmission.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

Query products with filters.

bash
curl "https://api.purch.xyz/search?q=headphones&priceMax=100"

Parameters:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

Query products with filters.

bash
curl "https://api.purch.xyz/search?q=headphones&priceMax=100"

Parameters:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 452)May include surrounding context.

Query products with filters.

bash
curl "https://api.purch.xyz/search?q=headphones&priceMax=100"

Parameters:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 494)May include surrounding context.

Query products with filters.

bash
curl "https://api.purch.xyz/search?q=headphones&priceMax=100"

Parameters:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

Natural language product search. Returns 20+ products from both Amazon and Shopify.

bash
curl -X POST "https://api.purch.xyz/shop" \
  -H "Content-Type: application/json" \
  -d '{"message": "comfortable running shoes under $100"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The /buy examples instruct users to transmit sensitive personal data including full shipping address, phone number, email, wallet address, and purchase details to an external API without any explicit privacy or handling warning. This can lead to unintentional disclosure of PII and transactional metadata to a third party, especially in agent-driven workflows where users may not realize what is being sent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The documented /buy example for Amazon on Solana sends full PII and wallet data to an external API to generate a payment transaction. In context, this is especially sensitive because it initiates a real-commerce and crypto-payment workflow, making mistakes or unauthorized use materially harmful.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

Amazon Products (Solana):

bash
curl -X POST "https://api.purch.xyz/buy" \
  -H "Content-Type: application/json" \
  -d '{
    "asin": "B0CXYZ1234",

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This Base/EVM /buy example similarly sends personal and wallet information to an external order-creation service. Since it supports downstream blockchain payment, misuse can expose both private user data and funds-related actions.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

Amazon Products (Base):

bash
curl -X POST "https://api.purch.xyz/buy" \
  -H "Content-Type: application/json" \
  -d '{
    "asin": "B0CXYZ1234",

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The Shopify /buy example transmits product URL, variant ID, email, wallet address, and shipping details to a third-party API. This creates meaningful privacy and transaction risk because the data can identify the user, their intended purchase, and the wallet involved in payment.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

Shopify Products - Use productUrl AND variantId:

bash
curl -X POST "https://api.purch.xyz/buy" \
  -H "Content-Type: application/json" \
  -d '{
    "productUrl": "https://store.com/products/item-name",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The signing examples normalize signing and submitting live blockchain transactions, including command lines that accept raw private keys, without a strong warning that this authorizes real payment on mainnet. In an agent skill, that omission is dangerous because users may execute examples or automate them without understanding they are irreversible financial operations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 452)May include surrounding context.

typescript
// 1. Search for products
const searchResponse = await fetch("https://api.purch.xyz/shop", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({ message: "wireless headphones under $100" })

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 494)May include surrounding context.

typescript
// 1. Search for products
const searchResponse = await fetch("https://api.purch.xyz/shop", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({ message: "wireless headphones under $100" })

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This duplicate /buy fetch again represents transmission of sensitive order and identity data to an external service as part of a real payment flow. The combination of PII and financial preparation raises the severity above ordinary network use.

Content

Scanner excerpt · SKILL.md (reported line 460)May include surrounding context.

md
const { products, reply } = await searchResponse.json();

// 2. User selects a product, create order (Solana wallet)
const orderResponse = await fetch("https://api.purch.xyz/buy", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({

Static analysis

No suspicious patterns detected.