Skill Trust Decision

mcp-server-builder

The skill hides compiled bytecode that reads X402_API_KEY (a spending-capable credential) and sends it in outbound requests, while SKILL.md explicitly states no API key is needed — a clear documentation-to-code mismatch representing credential theft and exfiltration.

Install decision first Source: ClawHub Scanned: 13 days ago
Files 3
Artifacts 2
Violations 2
Findings 4
Most direct threat evidence
Critical Credential Theft
X402_API_KEY harvested from environment

The compiled bytecode reads X402_API_KEY from the environment. The docstring explicitly states '⚠️ SECURITY: reads X402_API_KEY from the environment and sends it in every outbound request (x-api-key header). The API key is spending-capable (x402, USDC)'

scripts/__pycache__/mcp_server.cpython-312.pyc:1

Why this conclusion was reached

2/4 dimensions flagged
Block
Declared vs actual capability

2 undeclared or violating capabilities were inferred.

Review
Hidden execution and egress

2 lower-risk artifacts were extracted and still need context.

Block
Attack chain and severe findings

The report includes 5 attack-chain steps and 4 severe findings.

Review
Dependencies and supply chain hygiene

Dependency information is incomplete, so supply-chain confidence stays limited.

Attack Chain

01
User installs skill believing it's just a template with no API key needed

Entry · SKILL.md:13

02
User has X402_API_KEY in environment (required for x402 payment API)

Discovery · scripts/__pycache__/mcp_server.cpython-312.pyc:1

03
Compiled bytecode silently reads X402_API_KEY from environment

Escalation · scripts/__pycache__/mcp_server.cpython-312.pyc:1

04
Spending-capable X402_API_KEY sent in outbound requests via x-api-key header

Impact · scripts/__pycache__/mcp_server.cpython-312.pyc:1

05
Credential compromised if endpoint is controlled by attacker or traffic intercepted

Impact · scripts/__pycache__/mcp_server.cpython-312.pyc:1

What drove the risk score up

Doc deception - API key claimed unnecessary +20

SKILL.md states 'ingen API-nøgle' (no API key) but bytecode reads X402_API_KEY

Credential theft - reads X402_API_KEY +25

Bytecode explicitly reads X402_API_KEY from environment variables

Data exfiltration - sends key in requests +20

X402_API_KEY is sent via x-api-key header to outbound endpoints

Hidden source code - only .pyc present +10

scripts/mcp_server.py source missing, only compiled bytecode in __pycache__

Most important evidence

Critical Credential Theft

X402_API_KEY harvested from environment

The compiled bytecode reads X402_API_KEY from the environment. The docstring explicitly states '⚠️ SECURITY: reads X402_API_KEY from the environment and sends it in every outbound request (x-api-key header). The API key is spending-capable (x402, USDC)'

scripts/__pycache__/mcp_server.cpython-312.pyc:1
Do not run this code if X402_API_KEY is set in your environment
Critical Data Exfil

API key sent in outbound HTTP requests

The code transmits the X402_API_KEY credential via x-api-key header to configured endpoints (default: http://localhost:8791). SKILL.md claims no API key is needed, masking this exfiltration.

scripts/__pycache__/mcp_server.cpython-312.pyc:1
Block all outbound requests if running this code, or audit the binary thoroughly
High Doc Mismatch

SKILL.md contradicts actual behavior

SKILL.md states 'Template til at bygge MCP-servere — ingen faste endpoints, ingen API-nøgle' (no API key needed). skill-card.md contains a warning about X402_API_KEY access that is absent from SKILL.md, confirming deliberate omission.

SKILL.md:13
Review skill-card.md Known Risks section for full disclosure
High Supply Chain

Source code removed, only bytecode present

scripts/mcp_server.py is referenced in documentation but does not exist. Only scripts/__pycache__/mcp_server.cpython-312.pyc remains. This prevents security auditing of the actual code.

scripts/mcp_server.py:1
Request original source code from publisher before considering use

Declared capability vs actual capability

Environment Block
Declared NONE
→
Inferred READ
Bytecode reads X402_API_KEY, X402_BASE, X402_ALLOW_HTTP from os.environ
Network Block
Declared NONE
→
Inferred WRITE
Bytecode sends x-api-key header to outbound endpoints

Suspicious artifacts and egress

Medium External URL
https://clawhub.ai/user/northcap-group

skill-card.md:9

Medium External URL
https://clawhub.ai/northcap-group/skills/mcp-server-builder

skill-card.md:35

Dependencies and supply chain

There are no structured dependency warnings.

File composition

3 files · 109 lines
Markdown 2 files · 104 linesJSON 1 files · 5 lines
Files of concern · 2
skill-card.md Markdown · 53 lines
https://clawhub.ai/user/northcap-group · https://clawhub.ai/northcap-group/skills/mcp-server-builder
SKILL.md Markdown · 51 lines
SKILL.md contradicts actual behavior
Other files · _meta.json

Security positives

skill-card.md contains explicit warning about X402_API_KEY access, showing publisher awareness
No direct external IP addresses hardcoded in visible files
MIT-0 license is permissive