Back to skill

Security audit

LobPay

Security checks for vulnerabilities and agentic risk

Overview

The skill is for blockchain-backed purchases, but it handles wallet/API secrets and payment endpoints too loosely for automatic installation.

Review this skill carefully before installing. Use only a dedicated low-value wallet, prefer testnet, verify the LobPay API URL, avoid entering private keys in shared shells or CI logs, and do not let an agent run purchase commands without a clear item, amount, merchant, network, and endpoint confirmation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/buy.js:9
Finding

Unrestricted API endpoint can receive credentials and issue wallet-signed payment challenges

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/register.js:14
Finding

Wallet private key and API key are exposed through command-line arguments and plaintext local storage

Content
View full analysis
') console.log('Example: node register.js "Atla_Agent" 0xAddress 0xPrivateKey ak_live_xxx') process.exit(1) } const [agentName, address, privateKey, apiKey] = args ``` ```javascript // Save config if (!fs.existsSync(CONFIG_DIR)) { fs.mkdirSync(CONFIG_DIR, { recursive: true }) } fs.writeFileSync(CONFIG_FILE, JSON.stringify({ agentName, address: agentAddress.toLowerCase(), privateKey, apiKey, registeredAt: new Date().toISOString() }, null, 2)) ``` ```javascript console.log(`API Key: ${apiKey.slice(0, 20)}...`) ``` ### Technical Analysis The registration interface requires the wallet private key and API key to be supplied through `process.argv`. Command-line arguments can be exposed through: - Shell history. - Process-list inspection while the command is running. - Terminal session recording. - CI/CD and automation logs. - Command auditing and telemetry. - Parent-process error reporting. The script then stores both credentials unencrypted in `~/.lobpay/config.json`. Neither `mkdirSync` nor `writeFileSync` specifies an owner-only permission mode. The effective permissions therefore depend on the user's umask and the state of any pre-existing directory or file. The API key prefix is also printed to the terminal, creating an unnecessary partial disclosure. The private key is required for local transaction signing, but passing it through argv and keeping it in an ordinary plaintext JSON document are not necessary for that functionality. ### Attack Path 1. A user follows the documented registration syntax and supplies the wallet private key and API key on the command line. 2. The command is r ...[truncated 1245 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/package.json:6
Finding

Security-critical dependencies use floating version ranges without a lockfile

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (16)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description presents purchasing and payment capabilities without a prominent warning that actions may result in real merchant payments and irreversible blockchain transactions. Because the skill references Base Mainnet support and local private key usage, the lack of an upfront warning raises the chance that users or calling agents will treat it like a harmless informational tool and trigger costly actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The default API base URL is http://localhost:3000, and the script sends a Bearer API key plus payment-related request data to that endpoint. Using cleartext HTTP, even as a default, creates a risk of credential exposure or request tampering if the URL is changed to a non-local host, forwarded, proxied, containerized, or otherwise used outside a strictly local trust boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Accepting a private key on the command line exposes it to shell history, process listings, audit logs, and CI/job telemetry. That can leak the wallet secret to other local users, administrators, logging systems, or monitoring tools, enabling unauthorized transactions and account takeover.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script writes a raw private key and API key to a predictable file in the user's home directory without warning, encryption, or permission hardening. If the host is multi-user, backed up, compromised by malware, or if file permissions are too broad, these secrets can be recovered and used to impersonate the agent or steal wallet-controlled assets.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very broad commerce terms such as "Buy," "Purchase," "Pay," and "Checkout," which can cause the skill to activate in contexts where the user did not intend to initiate a blockchain-backed payment workflow. In a skill that can lead to real purchases and on-chain transactions, overly broad invocation materially increases the risk of unintended or premature payment actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
## 💰 X402 Payment Flow

1. **Checkout** → Get merchant wallet + pricing
2. **Sign** → Create X402 payment header
3. **Purchase** → Send to `/agents/purchase` with payment proof
4. **Confirm** → Transaction recorded on Base

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation describes an authenticated purchase endpoint that triggers X402 payment signing, on-chain settlement, and transaction recording, but it does not prominently warn that these actions can transfer funds and may be irreversible. In an agent-skill context, this omission is dangerous because an integrator or autonomous agent may treat the endpoint as a routine API call and execute real purchases without sufficient user confirmation or safety gating.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation instructs implementers to verify signatures, transfer tokens, and record transactions, but it does not warn that these actions move real funds and may be irreversible on-chain. In a payment-protocol integration guide, omission of financial-risk messaging can lead developers or users to test against mainnet, authorize token spending, or trigger unintended transfers without appreciating the consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs a real paid purchase immediately after fetching checkout information, with no explicit confirmation step or spending guard before calling the payment-enabled purchase endpoint. In a CLI skill that can be invoked by an agent or automation, this increases the risk of accidental or manipulated purchases, especially if product ID, quantity, or API base are influenced by untrusted input or environment configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code reads a private key from the user's config and immediately derives an account from it, which is a sensitive credential access operation. Although the script logs purchase activity, it does not disclose that it will access wallet credentials from disk or explain that behavior in comments/docstrings at this point.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

With no manifest available, this file appears from its code and user-facing output to be a local purchase-history viewer: it reads ~/.lobpay/history.json and prints transactions. However, it also imports axios and constructs an API base URL from an environment variable, despite never using network access in the implemented behavior, which introduces an unjustified capability relative to the script's apparent purpose.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency uses a caret range (^2.0.0), which allows newer minor and patch releases to be installed over time. That weakens build reproducibility and can unintentionally introduce vulnerable or malicious upstream changes into the agent skill's supply chain.

Content

Scanner excerpt · scripts/package.json (reported line 7)May include surrounding context.

json
"description": "LobPay Agent Skill - X402 commerce on Base",
  "type": "module",
  "dependencies": {
    "@x402/fetch": "^2.0.0",
    "@x402/evm": "^2.0.0",
    "viem": "^2.0.0",
    "axios": "^1.6.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency is version-ranged with a caret, so future installs may resolve to different releases than originally tested. In an agent that handles commerce and EVM interactions, this creates unnecessary supply-chain exposure if an upstream release introduces insecure behavior.

Content

Scanner excerpt · scripts/package.json (reported line 8)May include surrounding context.

json
"type": "module",
  "dependencies": {
    "@x402/fetch": "^2.0.0",
    "@x402/evm": "^2.0.0",
    "viem": "^2.0.0",
    "axios": "^1.6.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

Using ^2.0.0 for viem permits automatic drift to later compatible releases, reducing reproducibility and increasing supply-chain risk. Because this package is likely involved in blockchain/EVM operations, unexpected dependency changes could affect transaction handling or security-sensitive logic.

Content

Scanner excerpt · scripts/package.json (reported line 9)May include surrounding context.

json
"dependencies": {
    "@x402/fetch": "^2.0.0",
    "@x402/evm": "^2.0.0",
    "viem": "^2.0.0",
    "axios": "^1.6.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

Axios is not pinned to an exact version, so installs may pick up later 1.6.x releases without explicit review. This is more dangerous here because axios has a history of security advisories, making unreviewed drift more likely to introduce exploitable client-side or SSRF-related issues into the skill.

Content

Scanner excerpt · scripts/package.json (reported line 10)May include surrounding context.

json
"@x402/fetch": "^2.0.0",
    "@x402/evm": "^2.0.0",
    "viem": "^2.0.0",
    "axios": "^1.6.0"
  }
}

Unverifiable Dependency: axios has 16 known advisory(ies) (CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest references axios with a non-exact version while the package has multiple known advisories, so the actual installed version cannot be verified as safe. In a network-facing commerce agent, an affected axios release could expose the skill to SSRF, request smuggling, credential leakage, or similar HTTP-client abuses depending on how it is used elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/buy.js:9

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/checkout.js:6

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/feedback.js:6

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/history.js:6

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/register.js:8