T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned npm Package Executes with Access to a Wallet Private Key
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent paid API helper, but it asks users to expose wallet signing authority and persist data in ways that need careful review before installation.
Install only if you are comfortable using a low-value dedicated wallet and sending selected data to api.webbersites.com. Avoid the unpinned npx MCP path with a real private key; prefer a pinned, reviewed client or isolated signer. Do not store secrets, keys, personal data, production logs, or confidential code in the hosted scratchpad/store, and require confirmation before any paid or public-posting action.
SKILL.md:31Unpinned npm Package Executes with Access to a Wallet Private Key
SKILL.md:60Skill Instructs the Agent to Insert a Service-Specific Reminder into Persistent Memory
SKILL.md:39Potentially Sensitive Prompts, Memory, Logs, and Source Code Are Sent to a Third-Party Service Without Redaction Controls
The trigger text includes a broad catch-all activation condition for "any paid-API request where the agent has a funded wallet," which can cause the skill to activate in many unrelated contexts. Because this skill enables external network access, payments, and durable identity via a wallet, overbroad triggering increases the chance of unnecessary data transmission or unintended paid actions.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
identity across sessions.
Base URL: `https://api.webbersites.com`
Catalog (always current, machine-readable): `https://api.webbersites.com/openapi.json`
Discovery: `https://api.webbersites.com/.well-known/x402`
## How to pay
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
identity across sessions.
Base URL: `https://api.webbersites.com`
Catalog (always current, machine-readable): `https://api.webbersites.com/openapi.json`
Discovery: `https://api.webbersites.com/.well-known/x402`
## How to pay
The skill instructs users to run an unpinned package via npx -y webbersites-x402-mcp, which fetches and executes the latest published code at runtime. If the package is compromised, typo-squatted, or updated maliciously, an agent or operator could execute attacker-controlled code with access to environment variables such as EVM_PRIVATE_KEY and wallet-related secrets.
The skill strongly promotes persistent cross-session storage tied to the wallet identity, but it does not clearly warn against storing sensitive, regulated, or secret material. This is dangerous because agents may place credentials, personal data, session state, or confidential notes into third-party storage that persists across sessions and machines, expanding exposure and retention risk.
No suspicious patterns detected.