Back to skill

Security audit

Alby Bitcoin Payments Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a real bitcoin wallet payment skill, but it needs Review because it gives an agent ongoing payment authority and documents risky credential and install patterns.

Install only with a low-balance or budget-limited wallet, prefer named or file-based credentials over pasting raw NWC URLs, revoke any secret that appeared in chat or command history, pin and verify the CLI/install source where possible, and require explicit confirmation for every payment, swap, or paid fetch.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:25
Finding

Runtime Download and Execution of a Third-Party npm Package

Content
View full analysis
``` The same runtime execution pattern is repeatedly recommended for wallet operations, paid HTTP requests, authentication, and service discovery. ### Technical Analysis The skill directs the agent to use `npx -y`, which can download and immediately execute the `@getalby/cli` npm package without interactive confirmation. Pinning the package to version `0.8.0` reduces version-drift risk, but it does not provide cryptographic integrity verification, a vendored dependency, or an independently reviewed lockfile. The package executes with the privileges of the agent process and is deliberately given access to wallet credentials through `NWC_URL`, command-line options, or files under `~/.alby-cli/`. A compromised npm release, registry response, package-maintainer account, transitive dependency, or local npm configuration could therefore run code in a security-sensitive context. This behavior is necessary only insofar as the skill relies entirely on the external Alby CLI. Automatic runtime installation is not the minimum privilege implementation: the CLI could instead be installed and verified by an administrator before the skill runs. There is no evidence in the audited files that the named package or pinned release is currently malicious. The issue is the unverified download-and-execute trust model. ### Attack Path 1. An attacker compromises the npm package, one of its dependencies, a maintainer account, the package-resolution path, or the configured npm registry. 2. The agent follows the skill and invokes `npx -y @getalby/cli@0.8.0`. 3. `npx` retrieves and executes package-controlled lifecycle or CLI code without requesting confirmation. 4. The code runs with the agent's operating-system permissions. 5. Because wallet ...[truncated 927 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:157
Finding

Wallet Connection Secret Can Be Passed Through Process Command-Line Arguments

Content
View full analysis
` - either a file containing plaintext NWC connection secret (preferred), or a NWC connection secret (nostr+walletconnect://...). This argument is required for wallet commands. ``` ```bash npx -y @getalby/cli@0.8.0 connect "" ``` The README provides the same unsafe setup pattern: ```bash npx @getalby/cli connect "nostr+walletconnect://..." ``` ### Technical Analysis The skill permits, and during fallback setup explicitly demonstrates, passing a complete Nostr Wallet Connect connection secret as a command-line argument. Command-line arguments are not an appropriate transport for wallet credentials. Depending on the host and execution framework, arguments may be exposed through process-inspection interfaces, agent tool-call logs, shell history, audit telemetry, terminal recording, crash reports, job metadata, or monitoring products. Quoting the secret prevents ordinary shell word splitting but does not prevent disclosure through these channels. The instruction conflicts with the skill's own security requirement that connection secrets must never be pasted or shared in chat. An agent can only construct the illustrated command if the secret is introduced into its execution context, and that command may itself be retained in conversation or tool logs. The skill also provides safer alternatives, including passing a credential-file path and resolving `NWC_URL`. Consequently, accepting a raw secret through `-c` or `connect` exceeds the minimum exposure needed for wallet functionality. No confirmed malicious exfiltration endpoint was identified in the two audited Markdown files. The network use is intrinsic to Nostr Wallet Connect and paid API operations. The confirmed issue is credential e ...[truncated 1667 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (10)

YARA rule 'ransomware_behavior': Ransomware-like patterns (mass encryption, ransom notes) [malware]

Critical
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: alby-bitcoin-payments
description: teaches agents how to use @getalby/cli to operate a bitcoin lightning wallet via Nostr Wallet Connect (NIP-47). Use whenever the user wants to send or receive money, pay an invoice, check wallet balance, create invoices, convert between fiat and sats, retry an HTTP request that returned 402 Payment Required, or discover paid API services. Beyond lightning, it can pay to any on-chain cryptocurrency/stablecoin address (e.g. USDC/USDT) by automatically swapping from the bitcoin balance.
license: MIT-0
metadata:
  author: getAlby
  version: "1.3.8"
  openclaw:
    requires:
      env:
        - NWC_URL
      bins:
        - npx
      config:
        - ~/.alby-cli/
    primaryEnv: NWC_URL
    emoji: "🐝"
    homepage: https://getalby.com
---

# Usage

> **IMP

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes giving an agent an independent wallet interface and says it can operate on its own, but it does not include an explicit warning about autonomous fund movement, credential sensitivity, spending limits, or human approval expectations. Users may underestimate that this skill enables real monetary transfers and wallet management, which can lead to accidental loss or over-delegation. The autonomous payment context makes missing safety framing more dangerous than in an ordinary utility skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README tells users to run npx skills add getAlby/payments-skill without pinning a specific version. That allows whatever package version is current at execution time to run with the user's privileges, creating supply-chain risk if the package is compromised or a breaking change introduces unsafe behavior. In a wallet/payment skill, this is more dangerous because the installed tooling may later handle credentials and authorize fund transfers.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command npx @getalby/cli auth https://my.albyhub.com --app-name MyApp executes an unpinned package from the registry. Because this CLI is used to authenticate a wallet connection, a compromised or substituted package could capture wallet connection secrets, redirect authentication, or manipulate future payment operations. The payment context materially increases risk beyond a generic unpinned developer tool.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx @getalby/cli connect "nostr+walletconnect://..." without a fixed version. This is especially sensitive because the command handles a wallet connection secret directly; an untrusted or newly changed package could exfiltrate the secret and give attackers ongoing access to wallet functions. In a financial skill, this creates direct credential-theft and fund-loss risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Using npx @getalby/cli -w alice get-balance without version pinning still exposes users to supply-chain execution risk. While get-balance is less sensitive than connect/auth, the same package likely has access to local wallet configuration and could perform unauthorized actions if malicious. Given the skill's autonomous wallet scope, even seemingly read-only commands deserve stricter installation hygiene.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The skill relies on persistent wallet credentials via NWC_URL and files under ~/.alby-cli/, enabling ongoing access to payment capabilities across sessions. In an agent environment, persistent financial authority increases risk if the skill is triggered unexpectedly, misrouted, or later used by unrelated tasks.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: alby-bitcoin-payments
description: teaches agents how to use @getalby/cli to operate a bitcoin lightning wallet via Nostr Wallet Connect (NIP-47). Use whenever the user wants to send or receive money, pay an invoice, check wallet balance, create invoices, convert between fiat and sats, retry an HTTP request that returned 402 Payment Required, or discover paid API services. Beyond lightning, it can pay to any on-chain cryptocurrency/stablecoin address (e.g. USDC/USDT) by automatically swapping from the bitcoin balance.
license: MIT-0
metadata:
  author: getAlby

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description is broad enough to trigger this skill for many ordinary requests involving money, invoices, or HTTP 402 responses. Because the skill enables real financial operations, over-broad routing increases the chance an agent will invoke payment-capable behavior without sufficiently narrow user intent or additional confirmation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example prompt is written as a direct prescribed phrase in English: "What's your wallet balance". While minor, this can be read as steering invocation toward a specific language without documenting that other languages are acceptable or offering a language choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.