Back to skill

Security audit

Mythos Forge

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent, but it tells agents how to authorize real USDC payments without enough local validation or confirmation safeguards.

Install only if you are comfortable with a skill that can guide an agent through paid USDC commission requests. Before any commission, verify the exact amount, recipient, token, network, and service type yourself, and do not let an agent automatically sign or retry payment headers. Treat chat messages as public and keep API keys and private prompts out of them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:17
Finding

Unpinned Remote Skill Installation Permits Supply-Chain Substitution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:101
Finding

Server-Supplied Payment Parameters Are Signed Without Mandatory Local Validation

Content
View full analysis
Content-Type: application/json { "prompt": "Build a Next.js SaaS starter with Stripe, Supabase auth, and a dashboard", "agentId": "$MYTHOSFORGE_AGENT_ID" } ``` ```text x402 payment flow: 1. Send the POST without `X-PAYMENT` — server returns `402 Payment Required` with payment requirements 2. Parse the 402 response to get `payTo` address, `amount`, and `network` 3. Sign a USDC `TransferWithAuthorization` (EIP-712) and base64-encode it as `X-PAYMENT` 4. Resend the POST with the `X-PAYMENT` header — server verifies on-chain and delivers the result ``` ### Technical Analysis The documented workflow directs the client to parse `payTo`, `amount`, and `network` from an HTTP 402 response and sign a USDC `TransferWithAuthorization`. It does not require the client to compare those server-provided values against an independent local policy or the advertised service price. The instructions also omit mandatory checks for: - The exact Base mainnet chain ID. - The canonical USDC token contract. - An allowlisted recipient address. - The exact expected amount for the selected service. - EIP-712 domain fields and verifying contract. - Authorization validity boundaries. - A unique nonce and replay protection. - Explicit user confirmation before signing. EIP-712 signing provides integrity for the values that are signed, but it does not establish that those values are safe or intended. If a client blindly signs fields supplied by a compromised or misconfigured service, the signature faithfully authorizes the malicious parameters. ### Attack Path 1. An attacker compromises the API, deployment envi ...[truncated 1376 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

Server-Generated Agent Private Key Undermines Authentication Key Ownership

Content
View full analysis
dict: timestamp = int(time.time()) body_hash = sha256(json.dumps(payload, separators=(',', ':'))) message = sha256(f"{agent_id}{endpoint}{timestamp}{body_hash}") private_key = Ed25519PrivateKey.from_private_bytes(base64.b64decode(secret_key_b64)[:32]) sig = base64.b64encode(private_key.sign(message.encode())).decode() return {**payload, "agent_id": agent_id, "timestamp": timestamp, "signature": sig} ``` ### Technical Analysis The registration service generates and returns the Ed25519 private key to the client. This means the server necessarily possesses the key during provisioning and may retain it through application logs, response tracing, database storage, crash reports, or intentional server-side storage. As a result, the authentication mechanism cannot provide the claimed trustless key ownership. A server that knows or retains the private key can generate signatures indistinguishable from client-generated signatures. Compromise of stored registration data could likewise permi ...[truncated 1582 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs agents to initiate an x402 payment flow for USDC on Base, but it does not provide a prominent, explicit safety warning that this action triggers a real on-chain transfer of funds. In an agent-skill context, unclear payment disclosure increases the risk that a user or autonomous agent executes a commission request without informed consent, leading to unintended financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents an on-chain USDC payment flow and instructs agents to sign and submit X-PAYMENT authorizations without clearly warning that blockchain payments are financially consequential and may be irreversible once executed. This creates risk of unintended fund transfers, overpayment, or user confusion, particularly for autonomous agents that may follow the workflow mechanically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs agents to post messages to a live public chat but does not clearly warn that submitted content is publicly visible. An agent or user could inadvertently disclose sensitive prompts, credentials, internal context, or proprietary information, especially because the skill otherwise encourages authenticated interaction with the service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.