Back to skill

Security audit

X Search (x402)

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to perform paid X/Twitter searches as described, but it handles a wallet private key in ways that create significant credential and supply-chain risk.

Install only if you are comfortable giving this workflow access to a wallet key. Use a dedicated low-balance wallet, avoid storing the key in a project directory, restrict any config file to the current user, and treat the unpinned npx package as code that can change between searches.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
scripts/search.sh:47
Finding

Unpinned npm Package Is Downloaded and Executed with Access to a Payment Private Key

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search.sh:15
Finding

Payment Private Key Is Stored in Plaintext and Exported to a Third-Party Process

Content
View full analysis
/dev/null || echo "") if [ -n "$PRIVATE_KEY" ]; then export X402_PRIVATE_KEY="$PRIVATE_KEY" break fi fi done ``` `SKILL.md` recommends creating the plaintext credential file without setting restrictive permissions: ```bash echo '{"private_key": "0x..."}' > ~/.x402-config.json ``` ### Technical Analysis The documented configuration stores a cryptocurrency private key directly in a JSON file. The instructions do not set a restrictive `umask`, apply mode `0600`, verify ownership, or reject files readable by other users. Depending on the user's environment and default permissions, the resulting secret can be exposed to other local accounts, backups, synchronization tools, or accidental source-control commits. The search script then exports the recovered key as `X402_PRIVATE_KEY`. Exported environment variables are inherited by the subsequently executed npm package and any subprocesses it launches. This broadens access to a high-value financial credential beyond the minimal code responsible for signing a payment. The script also accepts configuration from the current working directory. Such files are more likely to be located in shared directories or project repositories and accidentally disclosed than a credential managed by a dedi ...[truncated 1281 chars]
Remediation
View remediation
"$HOME/.x402-config.json" chmod 600 "$HOME/.x402-config.json" ``` 4. Before reading the file, verify that it is a regular file, is owned by the current user, is not a symbolic link, and is not accessible to group or other users. Reject unsafe files rather than merely warning. 5. Remove current-directory credential discovery. Use one explicit, user-owned configuration location outside repositories and shared working directories. 6. Add `x402-config.json` and equivalent secret files to `.gitignore`, backup exclusions, and secret-scanning policies. 7. Avoid exporting the raw private key to a general-purpose third-party process. Perform signing in a separate minimal component and return only the signed authorization or transaction. 8. Clear temporary shell variables after use where practical and ensure errors, debugging output, and telemetry never include the secret. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation tells users to store a blockchain private key in a config file and even recommends a persistent home-directory location, but does not warn that this is a highly sensitive secret or advise restrictive file permissions. Because this skill performs paid requests, exposure of that key could let an attacker spend funds or impersonate the wallet owner.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill explicitly recommends persisting the private key in ~/.x402-config.json, which increases the attack surface and lifetime of a sensitive credential. Persistent wallet secrets are attractive targets for malware, local-user compromise, backups, shell-history leakage from creation commands, or accidental inclusion in tooling and repos.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

  1. Home directory: ~/.x402-config.json ← Recommended
  2. Working directory: $PWD/x402-config.json

Create the config file:

json
{
  "private_key": "0x1234567890abcdef..."

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs users to run an npx CLI tool without identifying or pinning an exact package name and version, which creates supply-chain risk from executing mutable remote code. In this context, the tool is also tied to payment handling and wallet credentials, so compromise could lead to credential theft or unauthorized blockchain transactions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The search skill reads a sensitive payment private key from local files and exports it into the environment before invoking a third-party package. Although payment may be part of the x402 workflow, this materially expands the trust boundary: an externally fetched tool receives access to signing credentials, so any compromise of that tool or its dependencies can expose or misuse the key.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/search.sh (reported line 40)May include surrounding context.

sh
echo ""
    echo "Please configure your private key using one of these methods:"
    echo "1. Set environment variable: export X402_PRIVATE_KEY=\"0x...\""
    echo "2. Create x402-config.json in current directory with:"
    echo '   {"private_key": "0x..."}'
    echo "3. Create ~/.x402-config.json in your home directory"
    exit 1

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The script executes an npm package via npx -y without pinning an exact version, so each run may fetch and execute whatever code is currently published under that package name. This creates a supply-chain risk: if the package is compromised, updated maliciously, or replaced through account compromise, the script will run attacker-controlled code in a context where a payment private key may already be present in the environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.