T08 · Insecure Dependencies
- Location
scripts/search.sh:47- Finding
Unpinned npm Package Is Downloaded and Executed with Access to a Payment Private Key
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to perform paid X/Twitter searches as described, but it handles a wallet private key in ways that create significant credential and supply-chain risk.
Install only if you are comfortable giving this workflow access to a wallet key. Use a dedicated low-balance wallet, avoid storing the key in a project directory, restrict any config file to the current user, and treat the unpinned npx package as code that can change between searches.
scripts/search.sh:47Unpinned npm Package Is Downloaded and Executed with Access to a Payment Private Key
scripts/search.sh:15Payment Private Key Is Stored in Plaintext and Exported to a Third-Party Process
The documentation tells users to store a blockchain private key in a config file and even recommends a persistent home-directory location, but does not warn that this is a highly sensitive secret or advise restrictive file permissions. Because this skill performs paid requests, exposure of that key could let an attacker spend funds or impersonate the wallet owner.
The skill explicitly recommends persisting the private key in ~/.x402-config.json, which increases the attack surface and lifetime of a sensitive credential. Persistent wallet secrets are attractive targets for malware, local-user compromise, backups, shell-history leakage from creation commands, or accidental inclusion in tooling and repos.
~/.x402-config.json ← Recommended$PWD/x402-config.jsonCreate the config file:
{
"private_key": "0x1234567890abcdef..."
The skill instructs users to run an npx CLI tool without identifying or pinning an exact package name and version, which creates supply-chain risk from executing mutable remote code. In this context, the tool is also tied to payment handling and wallet credentials, so compromise could lead to credential theft or unauthorized blockchain transactions.
The search skill reads a sensitive payment private key from local files and exports it into the environment before invoking a third-party package. Although payment may be part of the x402 workflow, this materially expands the trust boundary: an externally fetched tool receives access to signing credentials, so any compromise of that tool or its dependencies can expose or misuse the key.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
echo ""
echo "Please configure your private key using one of these methods:"
echo "1. Set environment variable: export X402_PRIVATE_KEY=\"0x...\""
echo "2. Create x402-config.json in current directory with:"
echo ' {"private_key": "0x..."}'
echo "3. Create ~/.x402-config.json in your home directory"
exit 1
The script executes an npm package via npx -y without pinning an exact version, so each run may fetch and execute whatever code is currently published under that package name. This creates a supply-chain risk: if the package is compromised, updated maliciously, or replaced through account compromise, the script will run attacker-controlled code in a context where a payment private key may already be present in the environment.
No suspicious patterns detected.