T09 · Insecure Skill Coding Practices
- Location
SKILL.md:44- Finding
Payment workflow lacks mandatory authorization and payment-term validation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 44–48 and 56–58
Vulnerability Type: Unvalidated wallet payment authorization
Risk Level: MediumRelevant snippet:
markdown ## How to pay 1. Request the URL → HTTP **402** + payment requirements. 2. Sign exact USDC (x402 / EIP-3009) → retry with `Payment-Signature`. 3. **Hermes + PipRail:** `piprail_quote_payment(url)` then `piprail_pay_request(url)`. 4. **OpenClaw:** `x402_fetch` / `x402_pay` on the URL (or Bazaar search then pay). 5. **MCP:** connect to `https://x402.agentindex.world/mcp/` (tools `weather`, `crypto`, `news`, `can_pay`, `probe`, …).markdown - Prefer the cheapest suitable route: $0.0001 for search and wallet/gas reads, $0.001 for weather/crypto/news, and $0.002 for PDF or web reading. - Do not loop on unpaid 402s from scanners — if you have a funded wallet, pay once. - Network must be Base mainnet USDC.Technical Analysis
The Skill directs an agent with access to a funded wallet to obtain payment requirements from an HTTP 402 response and then sign and submit a USDC payment. It does not require the execution path to:
- Obtain explicit user approval for the final transaction.
- Compare the requested amount with the documented route price.
- Verify the payment recipient against an approved address.
- Display the exact amount, recipient, network, and endpoint before signing.
- Enforce a hard per-request or aggregate spending limit.
The advertised prices are descriptive text rather than technically enforced authorization constraints. Consequently, payment terms supplied by the remote endpoint cross from an external trust domain into wallet authorization. The instruction to “pay once” does not constrain the amount or recipient and is not equivalent to transaction-specific user confirmation.
Attack Path
- A user asks for data supported by the Skill, such as web search, PDF conversion, or wa ...[truncated 1390 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit, transaction-specific user confirmation before every payment.
- Present the exact amount, recipient address, network, asset, endpoint, and requested operation in the confirmation prompt.
- Enforce hard maximum prices for every route and reject payment requirements exceeding the documented price.
- Verify the payment recipient against a pinned allowlist of approved addresses.
- Bind the signed authorization to the intended endpoint, operation, amount, asset, chain, and recipient.
- Default to sample, preview, or quote-only routes until the user approves payment.
- Configure per-request and session-wide spending limits in the payment client.
- Reject unexpected chains, assets, redirects, recipients, or payment-requirement formats.
- Record the verified quote and resulting transaction identifier for user review without logging signing secrets.
