Back to skill

Security audit

USDC Escrow

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it should be reviewed because it can trigger escrow fund actions through unauthenticated API calls with little user confirmation.

Install only if you are comfortable with a third-party escrow API that, as documented, exposes financial state changes without caller authentication. Treat create, release, resolve, and claim commands as live value-affecting operations, verify the backend and network before use, and require explicit human approval before any fund-moving command.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/api-docs.md:13
Finding

Unauthenticated privileged escrow operations through a shared server wallet

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (24)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation states that state-changing endpoints such as release, dispute, resolve, and claim-expired require no authentication, while simultaneously claiming only specific roles may invoke them. If implemented as documented, any unauthenticated caller could trigger escrow releases, dispute actions, or refunds, directly enabling unauthorized movement of funds. In an escrow/payment skill, this contradiction is especially dangerous because these operations have immediate financial consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This script performs an irreversible dispute-resolution action that determines where escrowed funds are sent, but it provides no confirmation prompt, dry-run mode, or explicit warning before submitting the request. In an agent-driven or scripted environment, a mistaken parameter, automation bug, or prompt-influenced invocation could immediately release or refund funds without a human verification step.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes shell scripts but does not declare any explicit tool scope or permissions boundary. In an agent environment, this can cause the orchestrator or user to underestimate that the skill can make networked shell calls, increasing the chance of unintended execution against a live financial backend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown instructs agents to create, release, dispute, and resolve escrows involving real USDC without prominent warnings that these actions can be irreversible and financially consequential. Because the skill is specifically for payments on-chain, an agent or operator could trigger value-transferring actions from simple commands without adequate confirmation, leading to loss of funds or unauthorized payment release.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 6)May include surrounding context.

Base URL

text
https://api.payclawback.xyz/api

Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 47)May include surrounding context.

Base URL

text
https://api.payclawback.xyz/api

Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 101)May include surrounding context.

Base URL

text
https://api.payclawback.xyz/api

Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 104)May include surrounding context.

Base URL

text
https://api.payclawback.xyz/api

Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 107)May include surrounding context.

Base URL

text
https://api.payclawback.xyz/api

Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 146)May include surrounding context.

Base URL

text
https://api.payclawback.xyz/api

Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 175)May include surrounding context.

Base URL

text
https://api.payclawback.xyz/api

Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 205)May include surrounding context.

Base URL

text
https://api.payclawback.xyz/api

Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 240)May include surrounding context.

Base URL

text
https://api.payclawback.xyz/api

Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 271)May include surrounding context.

Base URL

text
https://api.payclawback.xyz/api

Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 300)May include surrounding context.

Base URL

text
https://api.payclawback.xyz/api

Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 45)May include surrounding context.

}

text

**curl Example:**
```bash
curl -s -X POST "https://api.payclawback.xyz/api/escrows" \
  -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The release endpoint performs an irreversible transfer of escrowed funds but the documentation does not warn users or integrators about the permanence of the action. In agent-driven workflows, absence of confirmation language increases the likelihood of accidental releases or misuse by downstream automation. Because the operation moves money, missing warnings are security-relevant rather than merely UX issues.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill metadata presents simple escrow commands, but the API documentation exposes additional high-authority capabilities including unilateral dispute resolution and reclaiming expired funds. This mismatch can cause integrators or downstream agents to invoke more powerful actions than users expect, increasing the chance of unauthorized or unsafe fund handling. In an agent-to-agent payment context, hidden or under-disclosed financial powers materially raise risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The dispute resolution endpoint can either pay the beneficiary or refund the depositor, yet the documentation lacks a warning that the action is final and directly determines fund destination. In a system where an agent may call APIs automatically, this omission increases the risk of accidental or premature adjudication. Because this endpoint acts with arbiter-level authority, the impact of mistakes is higher than ordinary state changes.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-docs.md (reported line 238)May include surrounding context.

}

text

**curl Example:**
```bash
curl -s -X POST "https://api.payclawback.xyz/api/escrows/1/resolve" \
  -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The claim-expired endpoint reclaims escrowed funds to the depositor and changes the escrow state, but the documentation omits any warning about these effects. In an automation context, agents may invoke it without users understanding that funds will be recovered immediately once conditions are met. For a payment escrow skill, silent fund-reclamation behavior is risky.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/create-escrow.sh (reported line 18)May include surrounding context.

sh
DESCRIPTION="$3"
DEADLINE_HOURS="$4"

curl -s -X POST "${API_URL}/api/escrows" \
  -H "Content-Type: application/json" \
  -d "{
    \"beneficiary\": \"${BENEFICIARY}\",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script performs an irreversible state-changing release operation immediately when invoked, with no interactive confirmation, dry-run mode, or secondary validation of the target escrow. In the context of a payment/escrow skill, accidental invocation, wrong escrow IDs, or automation mistakes can cause unauthorized or unintended fund release, making the absence of safety checks materially risky.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/resolve-dispute.sh (reported line 17)May include surrounding context.

sh
ESCROW_ID="$1"
RELEASE_TO_BENEFICIARY="$2"

curl -s -X POST "${API_URL}/api/escrows/${ESCROW_ID}/resolve" \
  -H "Content-Type: application/json" \
  -d "{\"release_to_beneficiary\": ${RELEASE_TO_BENEFICIARY}}" | jq .

Static analysis

No suspicious patterns detected.