mcp-server-builder
The skill hides compiled bytecode that reads X402_API_KEY (a spending-capable credential) and sends it in outbound requests, while SKILL.md explicitly states no API key is needed — a clear documentation-to-code mismatch representing credential theft and exfiltration.
The compiled bytecode reads X402_API_KEY from the environment. The docstring explicitly states '⚠️ SECURITY: reads X402_API_KEY from the environment and sends it in every outbound request (x-api-key header). The API key is spending-capable (x402, USDC)'
scripts/__pycache__/mcp_server.cpython-312.pyc:1 为什么得出这个结论
2/4 个维度触发发现 2 项声明之外的能力或越权行为。
提取到 2 个一般风险产物,需要结合上下文判断。
报告包含 5 步攻击链,另有 4 项高危或严重发现。
没有完整依赖信息,供应链判断需要保留弹性。
攻击链
初始入口 · SKILL.md:13
内部探测 · scripts/__pycache__/mcp_server.cpython-312.pyc:1
权限提升 · scripts/__pycache__/mcp_server.cpython-312.pyc:1
最终危害 · scripts/__pycache__/mcp_server.cpython-312.pyc:1
最终危害 · scripts/__pycache__/mcp_server.cpython-312.pyc:1
风险分是怎么被拉高的
SKILL.md states 'ingen API-nøgle' (no API key) but bytecode reads X402_API_KEY
Bytecode explicitly reads X402_API_KEY from environment variables
X402_API_KEY is sent via x-api-key header to outbound endpoints
scripts/mcp_server.py source missing, only compiled bytecode in __pycache__
最关键的证据
X402_API_KEY harvested from environment
The compiled bytecode reads X402_API_KEY from the environment. The docstring explicitly states '⚠️ SECURITY: reads X402_API_KEY from the environment and sends it in every outbound request (x-api-key header). The API key is spending-capable (x402, USDC)'
scripts/__pycache__/mcp_server.cpython-312.pyc:1 API key sent in outbound HTTP requests
The code transmits the X402_API_KEY credential via x-api-key header to configured endpoints (default: http://localhost:8791). SKILL.md claims no API key is needed, masking this exfiltration.
scripts/__pycache__/mcp_server.cpython-312.pyc:1 SKILL.md contradicts actual behavior
SKILL.md states 'Template til at bygge MCP-servere — ingen faste endpoints, ingen API-nøgle' (no API key needed). skill-card.md contains a warning about X402_API_KEY access that is absent from SKILL.md, confirming deliberate omission.
SKILL.md:13 Source code removed, only bytecode present
scripts/mcp_server.py is referenced in documentation but does not exist. Only scripts/__pycache__/mcp_server.cpython-312.pyc remains. This prevents security auditing of the actual code.
scripts/mcp_server.py:1 声明能力 vs 实际能力
Bytecode reads X402_API_KEY, X402_BASE, X402_ALLOW_HTTP from os.environ Bytecode sends x-api-key header to outbound endpoints 可疑产物与外联
https://clawhub.ai/user/northcap-group skill-card.md:9
https://clawhub.ai/northcap-group/skills/mcp-server-builder skill-card.md:35
依赖与供应链
没有结构化依赖告警。
文件构成
skill-card.md SKILL.md