T09 · Insecure Skill Coding Practices
- Location
SKILL.md:34- Finding
Remote Service Generates and Returns Wallet Private Keys
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is clearly for AgentPMT payments, but it gives an agent financial and wallet-signing powers without enough safeguards.
Review carefully before installing. Use this only if you intend an agent to spend AgentPMT credits, require explicit approval and a clear budget for every purchase, use a fresh limited wallet, avoid funding the remotely generated wallet with unrelated assets, do not sign server-provided messages unless they exactly match local intent, and pin dependencies in an isolated environment.
SKILL.md:34Remote Service Generates and Returns Wallet Private Keys
SKILL.md:125Server-Controlled Error Fields Can Influence Signed Messages
SKILL.md:27Security-Critical Python Dependencies Are Installed Without Version or Hash Pinning
The skill explicitly instructs an autonomous agent to create a wallet and purchase credits from an external service, but it does not require an explicit confirmation or warning about real-world financial charges and third-party account creation. In an agent context, this can lead to unintended spending, external account proliferation, and actions taken without informed user consent.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import requests
response = requests.post("https://www.agentpmt.com/api/external/agentaddress", timeout=30)
response.raise_for_status()
wallet = response.json()
wallet_address = wallet["evmAddress"].lower()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import requests
response = requests.post("https://www.agentpmt.com/api/external/agentaddress", timeout=30)
response.raise_for_status()
wallet = response.json()
wallet_address = wallet["evmAddress"].lower()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import requests
response = requests.post("https://www.agentpmt.com/api/external/agentaddress", timeout=30)
response.raise_for_status()
wallet = response.json()
wallet_address = wallet["evmAddress"].lower()
This finding duplicates the same purchase-initiation behavior at line 53 and represents a real financial-action risk, not just generic network use. The dangerous aspect is that an autonomous agent may execute a paid transaction path against a third-party service without explicit user acknowledgment.
"credits": 500,
"payment_method": "x402",
}
first = requests.post("https://www.agentpmt.com/api/external/credits/purchase", json=purchase, timeout=30)
if first.status_code == 402:
payment_required = first.headers["PAYMENT-REQUIRED"]
paid = requests.post(
This finding duplicates the same purchase-initiation behavior at line 53 and represents a real financial-action risk, not just generic network use. The dangerous aspect is that an autonomous agent may execute a paid transaction path against a third-party service without explicit user acknowledgment.
"credits": 500,
"payment_method": "x402",
}
first = requests.post("https://www.agentpmt.com/api/external/credits/purchase", json=purchase, timeout=30)
if first.status_code == 402:
payment_required = first.headers["PAYMENT-REQUIRED"]
paid = requests.post(
This finding duplicates the charge-authorizing retry step at line 56. Sending a payment signature to satisfy a 402 challenge is materially sensitive because it can consummate a financial transaction under automated control.
first = requests.post("https://www.agentpmt.com/api/external/credits/purchase", json=purchase, timeout=30)
if first.status_code == 402:
payment_required = first.headers["PAYMENT-REQUIRED"]
paid = requests.post(
"https://www.agentpmt.com/api/external/credits/purchase",
json=purchase,
headers={"PAYMENT-SIGNATURE": "<base64 signed authorization>"},
This finding duplicates the charge-authorizing retry step at line 56. Sending a payment signature to satisfy a 402 challenge is materially sensitive because it can consummate a financial transaction under automated control.
first = requests.post("https://www.agentpmt.com/api/external/credits/purchase", json=purchase, timeout=30)
if first.status_code == 402:
payment_required = first.headers["PAYMENT-REQUIRED"]
paid = requests.post(
"https://www.agentpmt.com/api/external/credits/purchase",
json=purchase,
headers={"PAYMENT-SIGNATURE": "<base64 signed authorization>"},
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
session_response = requests.post("https://www.agentpmt.com/api/external/auth/session", json={
"wallet_address": wallet_address,
}, timeout=30)
session_response.raise_for_status()
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"request_id": "unique-balance-request-id", "signature": "0x...", } balance_response = requests.post("https://www.agentpmt.com/api/external/credits/balance", json=balance_payload, timeout=30) balance_response.raise_for_status()
No suspicious patterns detected.