Back to skill

Security audit

cpbox-local-descriptions

Security checks for vulnerabilities and agentic risk

Overview

The skill is for a paid place-description API, but its quick start asks users to run an unpinned npm payment helper that can change later and execute locally.

Review this before installing or following the quick start. Use a pinned, reviewed version of the payment helper, run it in a least-privileged environment, and require explicit transaction review or spending limits before allowing automatic x402 payments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:61
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 61-65
Vulnerability Type: Execution of an unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

bash
npx @springmint/x402-payment \
  --url "https://www.cpbox.io/api/x402/local-descriptions?ids=loc4CQWMJWLD4VBEBZ62XQLJTGK6YCJEEJDNAAAAAAA%3D" \
  --method GET

Technical Analysis

The documented command invokes @springmint/x402-payment through npx without specifying an exact package version or verifying package integrity. If the package is not already installed locally, npx may retrieve a mutable release from the configured package registry and immediately execute it.

This creates a supply-chain risk because the code executed by users can differ from the code that was available when the Skill was reviewed. Potential causes include compromise of the package publisher or registry account, publication of a malicious future release, or manipulation of the package source through registry configuration.

The package is presented as a payment helper. Consequently, it may execute in an environment containing wallet configuration, payment credentials, signing capabilities, or other ambient user permissions. The audit found no evidence that the current package is malicious; the vulnerability is the unsafe, unpinned execution method documented by the Skill.

Attack Path

  1. An attacker compromises the package publisher, distribution account, or another relevant part of the package supply chain.
  2. The attacker publishes a malicious release under the existing @springmint/x402-payment package name.
  3. A user follows the command in SKILL.md without specifying a trusted version.
  4. npx resolves and downloads the attacker-controlled release.
  5. The downloaded package executes locally with the permissions and ambient authority of the invoking user.
  6. The malicious package can access resources available to that user and may attempt to steal payment-related data, t ...[truncated 796 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the unversioned package reference with an exact, reviewed version, for example:

    bash
    npx --yes @springmint/x402-payment@<reviewed-exact-version> \
      --url "https://www.cpbox.io/api/x402/local-descriptions?ids=..." \
      --method GET
    
  2. Prefer installing the dependency into a controlled project with a committed lockfile rather than downloading and executing it on demand.

  3. Verify package provenance, publisher identity, release signatures where available, and registry integrity metadata before approving a version.

  4. Use package-manager integrity checks and a trusted registry configuration. Do not permit fallback to untrusted or user-controlled registries.

  5. Review updates before changing the pinned version and use automated dependency scanning to detect compromised or vulnerable releases.

  6. Run the payment helper in a least-privileged, isolated environment with access only to the credentials and files required for the specific transaction.

  7. Require explicit transaction review and authorization so that dependency code cannot silently approve arbitrary payments.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The documentation instructs users to execute npx @springmint/x402-payment without pinning an exact package version. npx will fetch the latest published package at runtime, so a compromised maintainer account, malicious update, or dependency-chain attack could cause arbitrary code execution on the user's machine. In this skill, that risk is more meaningful because the command is presented as a direct quick-start path for handling payments, increasing the chance that operators run it verbatim.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.