Back to skill

Security audit

glim.sh

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and not malicious, but it asks users to run unpinned npm commands that handle crypto wallet setup and payment-enabled MCP configuration.

Review carefully before installing the headless crypto flow. Prefer OAuth/prepaid balance if available, and only use the x402 path with a dedicated low-balance wallet, a pinned and verified x402-proxy version, and an understanding of what MCP configuration it changes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:46
Finding

Unpinned Third-Party Package Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 46-48
Vulnerability Type: Unpinned npm dependency execution
Risk Level: High

bash
npx x402-proxy setup                              # one-time: generate or import a wallet
npx x402-proxy wallet info                        # show address + USDC balance
npx x402-proxy mcp add glim https://glim.sh/mcp   # register glim in your MCP client behind a paying proxy

Technical Analysis

The documented commands instruct users to retrieve and execute x402-proxy through npx without specifying a version, integrity hash, lockfile, or signature verification mechanism. Consequently, the package version and effective code executed may change after the Skill has been reviewed.

This dependency is used for security-sensitive operations: generating or importing a cryptocurrency wallet, displaying wallet information, authorizing automatic payments, proxying MCP traffic, and changing MCP client configuration. An attacker who compromises the npm package, its publisher account, or its distribution process could cause arbitrary code to execute with the privileges of the user following these instructions.

No evidence establishes that the current package is malicious. The vulnerability is the unsafe, unpinned supply-chain execution pattern and the sensitive authority granted to the downloaded package.

Attack Path

  1. An attacker compromises the x402-proxy npm package, its publisher credentials, or a future release distributed under the same package name.
  2. The attacker publishes a modified package version containing malicious lifecycle or runtime code.
  3. A user follows SKILL.md and invokes one of the unversioned npx x402-proxy commands.
  4. npx resolves and downloads the attacker-controlled release.
  5. The downloaded package executes under the invoking user's account.
  6. The malicious code accesses wallet material or local configuration available to tha ...[truncated 837 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin x402-proxy to a specifically reviewed version rather than allowing npx to resolve an unspecified current release.
  • Verify the selected release against an authenticated integrity value or trusted package signature before execution.
  • Publish the expected package owner, source repository, version, and checksum so users can validate provenance.
  • Prefer a locked, auditable installation workflow over implicit download-and-execute behavior.
  • Review the package source and its dependency tree before recommending it for wallet operations.
  • Use a dedicated wallet containing only the minimum funds required for expected calls.
  • Avoid importing a high-value or general-purpose wallet into the proxy.
  • Require explicit transaction limits and user confirmation where supported, rather than granting unrestricted automatic payment authority.
  • Document where wallet keys are stored, which filesystem permissions protect them, and how users can revoke or rotate affected credentials.
  • Back up MCP configuration before modification and verify the resulting endpoint and proxy settings after setup.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to execute npx x402-proxy setup without pinning a specific package version or integrity hash, so the code fetched and executed can change over time. Because this command generates or imports a crypto wallet, compromise of the upstream package or a malicious update could directly expose private keys, redirect payments, or run arbitrary code on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The unpinned npx x402-proxy wallet info command executes whatever version of the package is current at runtime, creating a supply-chain risk. In this context the package interacts with wallet state and payment credentials, so a malicious or hijacked release could exfiltrate addresses, balances, configuration, or execute arbitrary code on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill tells users to run npx x402-proxy mcp add glim https://glim.sh/mcp without pinning the package version, which means an attacker who compromises the package distribution path could achieve arbitrary code execution during setup. This is especially sensitive because the command registers a payment-capable proxy in the MCP client and may handle wallet material and outbound billing flows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The REST API section recommends npx x402-proxy <url> as a paying curl without specifying a fixed version, again exposing users to mutable remote code execution via the npm supply chain. While this instance is slightly less sensitive than wallet setup, it still may process payment challenges and local configuration, making compromise materially dangerous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.