安全决策报告

mcp-server-builder

The skill hides compiled bytecode that reads X402_API_KEY (a spending-capable credential) and sends it in outbound requests, while SKILL.md explicitly states no API key is needed — a clear documentation-to-code mismatch representing credential theft and exfiltration.

安装决策优先 来源: ClawHub 扫描时间: 13 天前
文件 3
IOC 2
越权项 2
发现 4
最直接的威胁证据
严重 凭证窃取
X402_API_KEY harvested from environment

The compiled bytecode reads X402_API_KEY from the environment. The docstring explicitly states '⚠️ SECURITY: reads X402_API_KEY from the environment and sends it in every outbound request (x-api-key header). The API key is spending-capable (x402, USDC)'

scripts/__pycache__/mcp_server.cpython-312.pyc:1

为什么得出这个结论

2/4 个维度触发
阻止
声明与实际能力

发现 2 项声明之外的能力或越权行为。

复核
隐藏执行与外联

提取到 2 个一般风险产物,需要结合上下文判断。

阻止
攻击链与高危发现

报告包含 5 步攻击链,另有 4 项高危或严重发现。

复核
依赖与供应链卫生

没有完整依赖信息,供应链判断需要保留弹性。

攻击链

01
User installs skill believing it's just a template with no API key needed

初始入口 · SKILL.md:13

02
User has X402_API_KEY in environment (required for x402 payment API)

内部探测 · scripts/__pycache__/mcp_server.cpython-312.pyc:1

03
Compiled bytecode silently reads X402_API_KEY from environment

权限提升 · scripts/__pycache__/mcp_server.cpython-312.pyc:1

04
Spending-capable X402_API_KEY sent in outbound requests via x-api-key header

最终危害 · scripts/__pycache__/mcp_server.cpython-312.pyc:1

05
Credential compromised if endpoint is controlled by attacker or traffic intercepted

最终危害 · scripts/__pycache__/mcp_server.cpython-312.pyc:1

风险分是怎么被拉高的

Doc deception - API key claimed unnecessary +20

SKILL.md states 'ingen API-nøgle' (no API key) but bytecode reads X402_API_KEY

Credential theft - reads X402_API_KEY +25

Bytecode explicitly reads X402_API_KEY from environment variables

Data exfiltration - sends key in requests +20

X402_API_KEY is sent via x-api-key header to outbound endpoints

Hidden source code - only .pyc present +10

scripts/mcp_server.py source missing, only compiled bytecode in __pycache__

最关键的证据

严重 凭证窃取

X402_API_KEY harvested from environment

The compiled bytecode reads X402_API_KEY from the environment. The docstring explicitly states '⚠️ SECURITY: reads X402_API_KEY from the environment and sends it in every outbound request (x-api-key header). The API key is spending-capable (x402, USDC)'

scripts/__pycache__/mcp_server.cpython-312.pyc:1
Do not run this code if X402_API_KEY is set in your environment
严重 数据外泄

API key sent in outbound HTTP requests

The code transmits the X402_API_KEY credential via x-api-key header to configured endpoints (default: http://localhost:8791). SKILL.md claims no API key is needed, masking this exfiltration.

scripts/__pycache__/mcp_server.cpython-312.pyc:1
Block all outbound requests if running this code, or audit the binary thoroughly
高危 文档欺骗

SKILL.md contradicts actual behavior

SKILL.md states 'Template til at bygge MCP-servere — ingen faste endpoints, ingen API-nøgle' (no API key needed). skill-card.md contains a warning about X402_API_KEY access that is absent from SKILL.md, confirming deliberate omission.

SKILL.md:13
Review skill-card.md Known Risks section for full disclosure
高危 供应链

Source code removed, only bytecode present

scripts/mcp_server.py is referenced in documentation but does not exist. Only scripts/__pycache__/mcp_server.cpython-312.pyc remains. This prevents security auditing of the actual code.

scripts/mcp_server.py:1
Request original source code from publisher before considering use

声明能力 vs 实际能力

环境变量 阻止
声明 NONE
→
推断 READ
Bytecode reads X402_API_KEY, X402_BASE, X402_ALLOW_HTTP from os.environ
网络访问 阻止
声明 NONE
→
推断 WRITE
Bytecode sends x-api-key header to outbound endpoints

可疑产物与外联

中危 外部 URL
https://clawhub.ai/user/northcap-group

skill-card.md:9

中危 外部 URL
https://clawhub.ai/northcap-group/skills/mcp-server-builder

skill-card.md:35

依赖与供应链

没有结构化依赖告警。

文件构成

3 个文件 · 109 行
Markdown 2 个文件 · 104 行JSON 1 个文件 · 5 行
需关注文件 · 2
skill-card.md Markdown · 53 行
https://clawhub.ai/user/northcap-group · https://clawhub.ai/northcap-group/skills/mcp-server-builder
SKILL.md Markdown · 51 行
SKILL.md contradicts actual behavior
其他文件 · _meta.json

安全亮点

skill-card.md contains explicit warning about X402_API_KEY access, showing publisher awareness
No direct external IP addresses hardcoded in visible files
MIT-0 license is permissive