T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Unpinned Remote Skill Installation Permits Supply-Chain Substitution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent, but it tells agents how to authorize real USDC payments without enough local validation or confirmation safeguards.
Install only if you are comfortable with a skill that can guide an agent through paid USDC commission requests. Before any commission, verify the exact amount, recipient, token, network, and service type yourself, and do not let an agent automatically sign or retry payment headers. Treat chat messages as public and keep API keys and private prompts out of them.
SKILL.md:17Unpinned Remote Skill Installation Permits Supply-Chain Substitution
SKILL.md:101Server-Supplied Payment Parameters Are Signed Without Mandatory Local Validation
SKILL.md:42Server-Generated Agent Private Key Undermines Authentication Key Ownership
The skill instructs agents to initiate an x402 payment flow for USDC on Base, but it does not provide a prominent, explicit safety warning that this action triggers a real on-chain transfer of funds. In an agent-skill context, unclear payment disclosure increases the risk that a user or autonomous agent executes a commission request without informed consent, leading to unintended financial loss.
The skill documents an on-chain USDC payment flow and instructs agents to sign and submit X-PAYMENT authorizations without clearly warning that blockchain payments are financially consequential and may be irreversible once executed. This creates risk of unintended fund transfers, overpayment, or user confusion, particularly for autonomous agents that may follow the workflow mechanically.
The skill instructs agents to post messages to a live public chat but does not clearly warn that submitted content is publicly visible. An agent or user could inadvertently disclose sensitive prompts, credentials, internal context, or proprietary information, especially because the skill otherwise encourages authenticated interaction with the service.
No suspicious patterns detected.