mcp-server-builder
The skill hides compiled bytecode that reads X402_API_KEY (a spending-capable credential) and sends it in outbound requests, while SKILL.md explicitly states no API key is needed — a clear documentation-to-code mismatch representing credential theft and exfiltration.
The compiled bytecode reads X402_API_KEY from the environment. The docstring explicitly states '⚠️ SECURITY: reads X402_API_KEY from the environment and sends it in every outbound request (x-api-key header). The API key is spending-capable (x402, USDC)'
scripts/__pycache__/mcp_server.cpython-312.pyc:1 Why this conclusion was reached
2/4 dimensions flagged2 undeclared or violating capabilities were inferred.
2 lower-risk artifacts were extracted and still need context.
The report includes 5 attack-chain steps and 4 severe findings.
Dependency information is incomplete, so supply-chain confidence stays limited.
Attack Chain
Entry · SKILL.md:13
Discovery · scripts/__pycache__/mcp_server.cpython-312.pyc:1
Escalation · scripts/__pycache__/mcp_server.cpython-312.pyc:1
Impact · scripts/__pycache__/mcp_server.cpython-312.pyc:1
Impact · scripts/__pycache__/mcp_server.cpython-312.pyc:1
What drove the risk score up
SKILL.md states 'ingen API-nøgle' (no API key) but bytecode reads X402_API_KEY
Bytecode explicitly reads X402_API_KEY from environment variables
X402_API_KEY is sent via x-api-key header to outbound endpoints
scripts/mcp_server.py source missing, only compiled bytecode in __pycache__
Most important evidence
X402_API_KEY harvested from environment
The compiled bytecode reads X402_API_KEY from the environment. The docstring explicitly states '⚠️ SECURITY: reads X402_API_KEY from the environment and sends it in every outbound request (x-api-key header). The API key is spending-capable (x402, USDC)'
scripts/__pycache__/mcp_server.cpython-312.pyc:1 API key sent in outbound HTTP requests
The code transmits the X402_API_KEY credential via x-api-key header to configured endpoints (default: http://localhost:8791). SKILL.md claims no API key is needed, masking this exfiltration.
scripts/__pycache__/mcp_server.cpython-312.pyc:1 SKILL.md contradicts actual behavior
SKILL.md states 'Template til at bygge MCP-servere — ingen faste endpoints, ingen API-nøgle' (no API key needed). skill-card.md contains a warning about X402_API_KEY access that is absent from SKILL.md, confirming deliberate omission.
SKILL.md:13 Source code removed, only bytecode present
scripts/mcp_server.py is referenced in documentation but does not exist. Only scripts/__pycache__/mcp_server.cpython-312.pyc remains. This prevents security auditing of the actual code.
scripts/mcp_server.py:1 Declared capability vs actual capability
Bytecode reads X402_API_KEY, X402_BASE, X402_ALLOW_HTTP from os.environ Bytecode sends x-api-key header to outbound endpoints Suspicious artifacts and egress
https://clawhub.ai/user/northcap-group skill-card.md:9
https://clawhub.ai/northcap-group/skills/mcp-server-builder skill-card.md:35
Dependencies and supply chain
There are no structured dependency warnings.
File composition
skill-card.md SKILL.md