Back to skill

Security audit

TWZRD Trust

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for payment-risk checks, but it asks agents to run remote-directed or floating payment tooling in a wallet/payment workflow.

Review before installing. The service purpose is clear, but only run fixed, reviewed commands and pinned package versions; do not execute command strings returned by TWZRD responses, do not let the skill self-update outside your trusted install channel, and confirm payment network, recipient, and amount before any signing step.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:354
Finding

Remote Preflight Response Can Direct Local Command Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 354–357
Vulnerability Type: Execution of a remotely supplied command
Risk Level: High

Vulnerable snippet:

text
Read `readiness_card.decision` and **`next_action.command`**:
- `block` -> abort. Do not sign or send (`next_action.step=do_not_pay`).
- `warn` / `allow` -> host pay path: run `gate_eval_live` (refuse transcript). Cap spend on warn.
  Paid trust is optional Path A only — never the protection completion criterion.

Technical Analysis

The Skill directs the Agent to read and run next_action.command, which is obtained from the remote preflight response served by https://intel.twzrd.xyz/v1/intel/preflight. No local allowlist, fixed command mapping, argument validation, executable pinning, or non-shell invocation constraint is specified before execution.

This crosses the boundary between untrusted remote response data and local command execution. The expected command may normally invoke the documented gate evaluation utility, but the response field itself is controlled by the remote service and can change independently of the reviewed Skill file.

Attack Path

  1. The Agent submits seller and payment information to the remote preflight endpoint.
  2. The endpoint returns a warn or allow decision together with next_action.command.
  3. The Skill instructs the Agent to run the returned command.
  4. A malicious service operator, compromised endpoint, or attacker capable of altering the authenticated service response substitutes an arbitrary command for the expected gate command.
  5. The Agent executes that command with its current local permissions.

Impact Assessment

Successful exploitation permits command execution with the privileges available to the Agent. Depending on those privileges, the command could read Agent-accessible files and credentials, modify project or user files, execute additional programs, or establish ...[truncated 234 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not execute command strings received from the preflight service.
  • Replace next_action.command with a constrained action identifier, such as gate_eval_live, and map that identifier to a fixed local implementation.
  • Allowlist all accepted actions and reject unknown response values.
  • Invoke a pinned local executable directly with a structured argument array rather than through a shell.
  • Validate every remotely supplied argument against a strict schema, including type, length, and permitted-value constraints.
  • Pin the expected executable or package version and verify its integrity before invocation.
  • Require explicit user confirmation if a response requests any action outside the predefined read-only gate workflow.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 377)May include surrounding context.

text

Read the graph card:
- `wash_flagged: true` -> hard-stop (preflight `block`, merchant `refuse`). Never
  warn / allow / quick / proceed. Intel surfaces never soft-allow. Gate default
  is refuse (`refuseWashFlagged: true`).
- `wash_flagged: false` -> evaluated, no wash. `wash_flagged: null` -> **never evaluated**

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains broad phrases such as 'before paying', 'shopping check', and 'check seller', which can cause the skill to activate in many ordinary conversations. Overbroad activation is risky here because the skill encourages network access and payment-related workflows, potentially steering agents into unnecessary external calls or purchase guidance.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

bash
# 1) FREE preflight on the seller you might pay (real base58 payTo only)
curl -sS -X POST https://intel.twzrd.xyz/v1/intel/preflight \
  -H 'content-type: application/json' \
  -d '{"seller_wallet":"46vMcwuC4sK11sB3gkLhyA7J7GEwfkhn5rFyDtihBwqe","price_usdc":0.002,"agent_intent":"preflight"}'

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs users to execute npx agentcash@latest, which pulls and runs the newest package version at execution time. In a security-sensitive payment workflow, an upstream compromise, typosquat, or malicious new release could immediately lead to arbitrary code execution or wallet/payment abuse on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

npx clawhub install twzrd-trust executes a remotely resolved package without an exact version pin. If the package or dependency chain is compromised, users following the skill could run attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

This is a second unpinned npx clawhub invocation with the same risk profile: remote code execution from whatever version resolves at runtime. Repetition increases the chance users will copy/paste the unsafe form.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 331)May include surrounding context.

bash
# Resource join — the source of truth — listed | live_402; counterparty settlement overlay is separate
curl -s "https://intel.twzrd.xyz/v1/intel/resources?limit=20"
# Ingested listing overlay (optional). PayAI status stays not_indexed. Base/Polygon wash often wash_unknown.
curl -s "https://intel.twzrd.xyz/v1/intel/x402-directory?limit=20"

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The command npx agentcash@latest onboard tells users to install and execute the latest version of a payment-related CLI. Because it is both unpinned and tied to wallet onboarding, compromise could directly affect credentials, wallet setup, or future payment operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

npx agentcash@latest balance again executes a floating remote package in a wallet/payment context. Even seemingly read-only commands can exfiltrate wallet metadata, alter configs, or stage follow-on compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This fetch command uses npx agentcash@latest to interact with paid resources, so a compromised package could execute arbitrary code or redirect/alter payment behavior. The surrounding context makes the risk more severe because users may run it in environments with funded wallets.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Another unpinned npx agentcash@latest fetch appears in a section about making a paid query. In a live payment path, executing arbitrary newly published code is especially dangerous because it can influence signing, destination selection, or secret handling.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 691)May include surrounding context.

md
V7 receipts stay Solana-settlement only.

**Completions is a different rail.**
`POST https://api.twzrd.xyz/v1/chat/completions` is Solana USDC only
($0.01, payTo `DB2s5PeotN1zwb9WpLQMAYqdHnf86SfjYUhbe1Nm8D1e`). A Base-only
client cannot settle that 402. Do not tell a Base completions buyer to pay
this host.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 707)May include surrounding context.

1) Free teaser (no auth)

bash
curl -s "https://intel.twzrd.xyz/v1/intel/merchant_card/GFpLvocNdEjnSsLH3VJQL6wGcjGxTbUBrj6fqN3Qe1Gs"
  • wash_flagged: true -> do not pay (default refuse). Stop here.

Rp1

Medium
Category
MCP Rug Pull
Confidence
76% confidence
Finding

pip install twzrd-mcp is not version-pinned, so users may receive an unreviewed future release. While this is a common packaging weakness, it is somewhat less acute than npx one-shot execution because it is a standard install flow rather than direct immediate remote execution.

Content

No source excerpt is available for this finding.

Rp1

Low
Category
MCP Rug Pull
Confidence
76% confidence
Finding

pip install twzrd-mcp is not version-pinned, so users may receive an unreviewed future release. While this is a common packaging weakness, it is somewhat less acute than npx one-shot execution because it is a standard install flow rather than direct immediate remote execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.