Back to skill

Security audit

x402 Agent Tools — Inference, Memory, Monitoring

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent paid API helper, but it asks users to expose wallet signing authority and persist data in ways that need careful review before installation.

Install only if you are comfortable using a low-value dedicated wallet and sending selected data to api.webbersites.com. Avoid the unpinned npx MCP path with a real private key; prefer a pinned, reviewed client or isolated signer. Do not store secrets, keys, personal data, production logs, or confidential code in the hosted scratchpad/store, and require confirmation before any paid or public-posting action.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:31
Finding

Unpinned npm Package Executes with Access to a Wallet Private Key

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:60
Finding

Skill Instructs the Agent to Insert a Service-Specific Reminder into Persistent Memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:39
Finding

Potentially Sensitive Prompts, Memory, Logs, and Source Code Are Sent to a Third-Party Service Without Redaction Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger text includes a broad catch-all activation condition for "any paid-API request where the agent has a funded wallet," which can cause the skill to activate in many unrelated contexts. Because this skill enables external network access, payments, and durable identity via a wallet, overbroad triggering increases the chance of unnecessary data transmission or unintended paid actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
identity across sessions.

Base URL: `https://api.webbersites.com`
Catalog (always current, machine-readable): `https://api.webbersites.com/openapi.json`
Discovery: `https://api.webbersites.com/.well-known/x402`

## How to pay

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
identity across sessions.

Base URL: `https://api.webbersites.com`
Catalog (always current, machine-readable): `https://api.webbersites.com/openapi.json`
Discovery: `https://api.webbersites.com/.well-known/x402`

## How to pay

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs users to run an unpinned package via npx -y webbersites-x402-mcp, which fetches and executes the latest published code at runtime. If the package is compromised, typo-squatted, or updated maliciously, an agent or operator could execute attacker-controlled code with access to environment variables such as EVM_PRIVATE_KEY and wallet-related secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill strongly promotes persistent cross-session storage tied to the wallet identity, but it does not clearly warn against storing sensitive, regulated, or secret material. This is dangerous because agents may place credentials, personal data, session state, or confidential notes into third-party storage that persists across sessions and machines, expanding exposure and retention risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.