Back to skill

Security audit

Agent Payment

Security checks for vulnerabilities and agentic risk

Overview

The skill is clearly for AgentPMT payments, but it gives an agent financial and wallet-signing powers without enough safeguards.

Review carefully before installing. Use this only if you intend an agent to spend AgentPMT credits, require explicit approval and a clear budget for every purchase, use a fresh limited wallet, avoid funding the remotely generated wallet with unrelated assets, do not sign server-provided messages unless they exactly match local intent, and pin dependencies in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:34
Finding

Remote Service Generates and Returns Wallet Private Keys

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:125
Finding

Server-Controlled Error Fields Can Influence Signed Messages

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Security-Critical Python Dependencies Are Installed Without Version or Hash Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs an autonomous agent to create a wallet and purchase credits from an external service, but it does not require an explicit confirmation or warning about real-world financial charges and third-party account creation. In an agent context, this can lead to unintended spending, external account proliferation, and actions taken without informed user consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

python
import requests

response = requests.post("https://www.agentpmt.com/api/external/agentaddress", timeout=30)
response.raise_for_status()
wallet = response.json()
wallet_address = wallet["evmAddress"].lower()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

python
import requests

response = requests.post("https://www.agentpmt.com/api/external/agentaddress", timeout=30)
response.raise_for_status()
wallet = response.json()
wallet_address = wallet["evmAddress"].lower()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

python
import requests

response = requests.post("https://www.agentpmt.com/api/external/agentaddress", timeout=30)
response.raise_for_status()
wallet = response.json()
wallet_address = wallet["evmAddress"].lower()

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This finding duplicates the same purchase-initiation behavior at line 53 and represents a real financial-action risk, not just generic network use. The dangerous aspect is that an autonomous agent may execute a paid transaction path against a third-party service without explicit user acknowledgment.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
"credits": 500,
    "payment_method": "x402",
}
first = requests.post("https://www.agentpmt.com/api/external/credits/purchase", json=purchase, timeout=30)
if first.status_code == 402:
    payment_required = first.headers["PAYMENT-REQUIRED"]
    paid = requests.post(

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This finding duplicates the same purchase-initiation behavior at line 53 and represents a real financial-action risk, not just generic network use. The dangerous aspect is that an autonomous agent may execute a paid transaction path against a third-party service without explicit user acknowledgment.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
"credits": 500,
    "payment_method": "x402",
}
first = requests.post("https://www.agentpmt.com/api/external/credits/purchase", json=purchase, timeout=30)
if first.status_code == 402:
    payment_required = first.headers["PAYMENT-REQUIRED"]
    paid = requests.post(

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This finding duplicates the charge-authorizing retry step at line 56. Sending a payment signature to satisfy a 402 challenge is materially sensitive because it can consummate a financial transaction under automated control.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
first = requests.post("https://www.agentpmt.com/api/external/credits/purchase", json=purchase, timeout=30)
if first.status_code == 402:
    payment_required = first.headers["PAYMENT-REQUIRED"]
    paid = requests.post(
        "https://www.agentpmt.com/api/external/credits/purchase",
        json=purchase,
        headers={"PAYMENT-SIGNATURE": "<base64 signed authorization>"},

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This finding duplicates the charge-authorizing retry step at line 56. Sending a payment signature to satisfy a 402 challenge is materially sensitive because it can consummate a financial transaction under automated control.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
first = requests.post("https://www.agentpmt.com/api/external/credits/purchase", json=purchase, timeout=30)
if first.status_code == 402:
    payment_required = first.headers["PAYMENT-REQUIRED"]
    paid = requests.post(
        "https://www.agentpmt.com/api/external/credits/purchase",
        json=purchase,
        headers={"PAYMENT-SIGNATURE": "<base64 signed authorization>"},

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

Step 3 — Create a Session

python
session_response = requests.post("https://www.agentpmt.com/api/external/auth/session", json={
    "wallet_address": wallet_address,
}, timeout=30)
session_response.raise_for_status()

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

"request_id": "unique-balance-request-id", "signature": "0x...", } balance_response = requests.post("https://www.agentpmt.com/api/external/credits/balance", json=balance_payload, timeout=30) balance_response.raise_for_status()

text

Static analysis

No suspicious patterns detected.