Back to skill

Security audit

Nostr Social

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it gives an agent real social-posting and wallet powers with under-scoped install, network, and file behaviors that deserve review before use.

Install only if you are comfortable giving the agent its own public Nostr identity and spend-capable wallet. Treat ~/.cocod/config.json and ~/.nostr/secret.key as high-value secrets, avoid funding the wallet until payment confirmations and dependency pinning are improved, and prefer reviewed, pinned installs over the documented GitHub clone or unpinned npx flows.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:18
Finding

Mutable Remote Repository Is Cloned and Executed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/nostr.js:969
Finding

Caller-Controlled State Path Allows Arbitrary File Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/nostr.js:399
Finding

Attacker-Controlled LNURL Callback Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
install.sh:6
Finding

Installation and Wallet Commands May Execute Mutable npm Packages

Content
View full analysis
/dev/null ``` ```json { "name": "nostr-skill", "type": "module", "dependencies": { "@scure/bip32": "^2.0.1", "@scure/bip39": "^2.0.1", "cocod": "^0.0.10", "nostr-tools": "^2.10.0", "ws": "^8.18.0" } } ``` ```bash # Create wallet (mnemonic saved to config file) npx cocod init # Derive Nostr identity from wallet mnemonic (NIP-06) node {SKILL_DIR}/scripts/nostr.js init # Get identity info NPUB=$(node {SKILL_DIR}/scripts/nostr.js whoami | grep npub | awk '{print $2}') LN_ADDR=$(npx cocod npc address) ``` ### Technical Analysis The installer uses `npm install`, which may execute dependency lifecycle scripts with the Agent's privileges. Although the audited lockfile resolves the observed packages from `registry.npmjs.org` and contains integrity metadata, the manifest uses caret version ranges and the installer does not explicitly require an unchanged lockfile. The setup instructions then use `npx cocod` without `--no-install` and without a fixed path to the locally installed binary. The installer places dependencies under `scripts/node_modules`, but the later command's working directory is not guaranteed to be `scripts`. If local package resolution fails, `npx` may offer to retrieve or execute registry content rather than failing closed. This dependency execution occurs in a workflow that creates a financial wallet and stores a mnemonic. A compromised dependency or unexpectedly downloaded CLI could access that sensitive material. ### Attack Path 1. The checked lockfile is omitted, modified, regenerated, or not honored in a future insta ...[truncated 1356 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (46)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description understates the breadth of capabilities actually exposed, including DMs, relay management, mention processing, and financial operations. Security reviewers and users may consent to a narrow identity bootstrap while unknowingly granting a much broader social and wallet automation surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description understates the breadth of capabilities actually exposed, including DMs, relay management, mention processing, and financial operations. Security reviewers and users may consent to a narrow identity bootstrap while unknowingly granting a much broader social and wallet automation surface.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script reads another application's wallet mnemonic from ~/.cocod/config.json and reuses it to derive a Nostr identity without an explicit consent gate at the point of access. A wallet mnemonic is highly sensitive root secret material; cross-application secret reuse increases blast radius, and compromise or unexpected behavior in this skill can expose both social identity and wallet backup domain together.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
97% confidence
Finding

The lockfile pins ws to version 8.19.0, which the finding reports as affected by two HIGH severity advisories: an uninitialized memory disclosure and a memory-exhaustion denial of service. In this skill, WebSocket connectivity is part of the Nostr networking stack, so a vulnerable ws library could expose sensitive agent traffic or allow a remote peer/relay to crash or degrade the agent service.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README makes a reassuring security claim that the agent never displays or transmits private keys, but later instructs the user to retrieve the mnemonic from a local config file. This contradiction can mislead users about secret-handling behavior and reduce caution around highly sensitive wallet and identity recovery material.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README states the skill does not read local files, yet other sections explicitly say it pulls profile data from SOUL.md and integrates with HEARTBEAT.md and TOOLS.md. This inconsistency is dangerous because it obscures the skill's actual local-data access, preventing users from accurately assessing privacy exposure and file-trust boundaries.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill performs networked actions and accesses persistent local files containing keys and wallet state, but it does not declare any explicit tool scope or permissions boundaries. That makes review, sandboxing, and policy enforcement weaker, increasing the chance the agent invokes sensitive capabilities without the operator realizing the full blast radius.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill establishes long-lived credentials and stores a wallet mnemonic in a persistent config file, creating durable compromise impact if the host or agent later reads or leaks those files. Persistence is expected for wallets, but it is still security-sensitive because one secret recovers both the Nostr identity and ecash wallet.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
### Step 1: Secure Setup (User Consent Required)

**SECURITY NOTICE:** This skill will create cryptographic keys for your agent. This requires:
- Creating Nostr identity keypair in `~/.nostr/secret.key`
- Creating Cashu wallet with backup seed in `~/.cocod/config.json`
- User must explicitly backup the mnemonic seed phrase

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Using npx cocod without pinning a version allows whatever package version is current at execution time to be fetched and run. In a key-management and wallet context, this is especially dangerous because a malicious or compromised upstream release could exfiltrate mnemonics, keys, invoices, or funds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The unpinned npx cocod invocation executes third-party code in a workflow that handles wallet initialization and sensitive seed material. That creates a supply-chain execution path where upstream changes can alter security behavior without notice.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

Using DiceBear with seed=${NPUB} causes the agent's persistent public identifier to be transmitted to an external service. While the key is public, this creates third-party correlation of the identity bootstrap event and ties the agent's profile generation to an external observer.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

If skipped, use DiceBear (deterministic, unique per npub):

bash
AVATAR="https://api.dicebear.com/7.x/shapes/png?seed=${NPUB}&size=400"
BANNER="https://api.dicebear.com/7.x/shapes/png?seed=${NPUB}-banner&size=1500x500"
node {SKILL_DIR}/scripts/nostr.js profile-set '{"picture":"'$AVATAR'","banner":"'$BANNER'"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

The banner URL similarly transmits a deterministic value derived from the public identifier to a third party, enabling correlation and external logging of profile setup. In a privacy-sensitive identity skill, unnecessary external disclosure should be minimized.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

If skipped, use DiceBear (deterministic, unique per npub):

bash
AVATAR="https://api.dicebear.com/7.x/shapes/png?seed=${NPUB}&size=400"
BANNER="https://api.dicebear.com/7.x/shapes/png?seed=${NPUB}-banner&size=1500x500"
node {SKILL_DIR}/scripts/nostr.js profile-set '{"picture":"'$AVATAR'","banner":"'$BANNER'"}'

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Broad natural-language triggers for posting and wallet actions can cause unintended invocation, especially in agents that interpret conversational text opportunistically. In this skill, accidental activation could publish unwanted messages, follow accounts, or initiate financial flows based on ambiguous user phrasing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown documents direct payment sending but does not require an explicit irreversible-transfer warning or confirmation at the point of execution. In a wallet skill, that omission materially raises the chance of accidental or socially engineered fund loss.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command path depends on an unpinned external package for payment-related operations. In a financial workflow, dynamic package resolution can turn a documentation command into arbitrary code execution with access to wallet state.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill documents balance and wallet operations through unversioned npx cocod calls, exposing users to upstream package compromise. Because these commands interact with a live wallet, the consequences can include fund loss or secret disclosure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

Wallet

bash
npx cocod balance
npx cocod receive bolt11 1000    # Create invoice
npx cocod send bolt11 <invoice>  # Pay invoice
npx cocod npc address            # Lightning address

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

An unpinned package is used for invoice creation and payment, which are highly sensitive financial actions. If the package changes maliciously or unexpectedly, it could redirect funds, alter invoices, or leak transaction metadata.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Paying invoices through an unpinned npx dependency introduces avoidable supply-chain risk into irreversible financial transfers. In this context, even a brief upstream compromise could directly lead to loss of funds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Retrieving wallet identity data via unpinned third-party code still exposes sensitive local wallet context to upstream code. In a skill that manages long-lived credentials, this is a meaningful trust-boundary failure.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/nostr.js:81