Back to skill

Security audit

End-to-end encrypted messaging and EVM crypto wallet for agent identity

Security checks for vulnerabilities and agentic risk

Overview

This skill is for encrypted messaging and crypto transfers, but it asks users to run unpinned npm code while handling private keys and funds.

Review carefully before installing. Use only a pinned, reviewed CLI version, avoid global installation when possible, do not paste real private keys into shell commands or agent chats, and independently verify chain, recipient, token contract, amount, and fees before any transfer.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:14
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis
``` The same unpinned `npx @openindex/openindexcli` invocation is repeated throughout `SKILL.md:31-213`. ### Technical Analysis The skill instructs users and agents to globally install or directly execute the latest available version of `@openindex/openindexcli`. It does not specify an exact version, lockfile, package integrity hash, trusted artifact digest, or other mechanism for verifying the downloaded executable. An `npx` invocation may download package code at execution time. Consequently, the effective code executed by the skill can change after the skill itself has been reviewed. A malicious package release, compromised publisher account, registry compromise, or dependency-chain compromise could introduce arbitrary code without any modification to `SKILL.md`. This is particularly sensitive because the external CLI is intended to process private keys, encrypted messages, identities, recipient addresses, and cryptocurrency transactions. The supplied project contains no implementation of the CLI, so its behavior and security claims cannot be independently verified from the audited artifact. ### Attack Path 1. An attacker compromises the npm package, its publisher account, or one of its transitive dependencies. 2. The attacker publishes a malicious version under the existing package name. 3. A user or agent follows the skill instructions and runs either: - `npm install -g @openindex/openindexcli`, or - `npx @openindex/openindexcli ...`. 4. The package manager downloads and executes the attacker-controlled package or lifecycle code. 5. The malicious code reads process-accessible secrets, environment variables, wallet keys, ...[truncated 990 chars]
Remediation
View remediation
``` Do not use version ranges or floating tags such as `latest`. 2. Publish and verify the expected package tarball integrity hash or cryptographic signature before execution. 3. Include a lockfile and retain reviewed dependency versions where a local installation is used. 4. Prefer vendoring the reviewed source code in the project or linking to a reproducible, signed release whose source and build process can be audited. 5. Avoid global installation unless it is operationally necessary. Execute the package in a restricted environment with minimal filesystem, network, and secret access. 6. Disable npm lifecycle scripts where compatible with the package: ```bash npm install --ignore-scripts --save-exact @openindex/openindexcli@X.Y.Z ``` 7. Review the CLI and all transitive dependencies before allowing it to handle wallet keys or authorize financial transactions. 8. Require explicit transaction confirmation that independently displays the resolved chain, recipient address, token contract, and amount. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:163
Finding

Private Keys Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (44)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

Group Messaging

bash
create-group <groupName> <creator> <member2> ...  # Create group (creator first, then members)
group-send <groupName> <message>                  # Send message to group
leave-group <groupName>                           # Leave group and trigger key rotation

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
# Alice creates a group (creator first, then members)
npx @openindex/openindexcli create-group project-team alice bob charlie -k ALICE_KEY

# Send messages to the group
npx @openindex/openindexcli group-send project-team "Meeting at 3pm tomorrow" -k ALICE_KEY

# Members retrieve group messages

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill repeatedly instructs users to execute the package via npx without pinning an exact version. This causes runtime code to be fetched from the registry at execution time, so a compromised publisher account, malicious new release, dependency hijack, or typo-replacement event could lead to arbitrary code execution on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documentation tells users to run npx @openindex/openindexcli without an exact version, which means unpinned code is downloaded and executed on demand. In a security-sensitive skill that handles private keys and crypto transfers, this materially increases the risk that a malicious or compromised release could steal credentials or funds.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions tell users to export a private key directly in the shell without warning about exposure through shell history, environment inspection, process listings in some contexts, logs, screenshots, or shared terminal sessions. Because this skill handles wallets and crypto transfers, mishandling the private key can immediately result in account compromise and theft.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command example invokes the CLI through npx without version pinning, allowing whatever the registry currently serves as latest to run locally. Because the surrounding workflow includes wallet creation, registration, and message handling, a malicious package update could capture private keys, plaintext messages, or redirect transfers.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Running npx @openindex/openindexcli without an exact version creates a supply-chain execution risk because the resolved artifact can change over time. In this skill, the context is especially sensitive since it deals with usernames, public keys, and cryptographic messaging setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to execute an unpinned package directly from the npm registry. That exposes users to arbitrary code execution if the upstream package or one of its delivered dependencies is compromised between the time the skill is read and the time the command is run.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This npx usage is unpinned and therefore susceptible to supply-chain compromise. Since the command is part of an encrypted messaging workflow, compromise could undermine confidentiality claims by exfiltrating local keys or decrypted content before encryption or after decryption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents irreversible crypto transfer commands but does not clearly warn that transfers cannot be undone and that users must verify recipient, chain, token contract, and amount before signing. In a username-based, multi-chain workflow, ambiguity and resolution mistakes materially increase the chance of permanent loss of funds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The transfer example executes an unpinned CLI from npm, meaning the code path handling funds can silently change. In the worst case, a malicious release could swap recipient resolution, alter chain selection, or siphon assets while appearing to perform a normal send.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx without version pinning for token transfer commands exposes users to remote code execution from whatever package release is current at invocation time. Because this example concerns token transfers, compromise could directly lead to theft of credentials or assets.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The generic command syntax shows execution of an unpinned npm package via npx, which introduces supply-chain risk throughout the skill. Any later command built from this syntax inherits the same risk that a changed package release could execute attacker-controlled code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This search example still uses npx without version pinning, which is risky because even apparently harmless commands can execute arbitrary install-time or runtime code. In a CLI that also manages private keys and transfers, any entry point may expose the same sensitive environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The unpinned npx invocation allows the executed code to drift with upstream releases. A compromised release could exploit even a search command to read local environment variables, wallet keys, or cached data, so the impact is not limited to the apparent function of the command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This roulette example fetches and runs the CLI without version pinning, preserving the same supply-chain code-execution risk as the rest of the document. Because the same CLI may later handle keys and messages, trust in the binary should be established once and fixed, not left to current registry state.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The wallet creation command is executed via unpinned npx, so the code generating or displaying secrets can change unexpectedly. A malicious release could generate predictable keys, print decoy addresses, or exfiltrate the newly created private key immediately.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This registration step relies on unpinned npx execution, which could allow a malicious package version to manipulate identity registration or leak key material used in the process. In identity-based messaging, compromise here can poison trust relationships and future communications.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The set-profile example invokes the CLI without a pinned version, exposing users to arbitrary code execution from a mutable upstream artifact. In this ecosystem, the same tool handles crypto operations, so a compromise during any command can impact all local secrets and funds.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This encrypted messaging example still executes unpinned code from npm. If a malicious release is delivered, it could capture plaintext before encryption, substitute recipient keys, or silently transmit copies of messages to an attacker.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The second send-message example repeats the same unpinned supply-chain risk. The command context makes it especially sensitive because confidentiality and authenticity claims can be defeated entirely if the client used to encrypt and sign messages is malicious.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Retrieving and decrypting messages through an unpinned CLI means a malicious package update could steal decrypted contents and keys at the moment of use. This is particularly dangerous because users may trust the E2E messaging claim while the local endpoint is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This reply example is another unpinned npx execution in a cryptographic messaging workflow. A compromised release could spoof sender identity, exfiltrate plaintext, or degrade key handling while still appearing to succeed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The inbox-checking example invokes the mutable latest package via npx, creating a direct risk to confidentiality of decrypted messages and local keys. The messaging context makes this more dangerous than a generic CLI because compromise defeats the core security promise of the skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This group registration example uses unpinned npx for identity-related operations, which means the trust setup for group messaging is performed by mutable remote code. A malicious release could register attacker-controlled keys or leak those supplied on the command line.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.