Intent-Code Divergence
Medium
- Confidence
- 97% confidence
- Finding
- The docstring states that x402Fetch requires an explicit confirmation flag, but the implementation automatically signs a payment authorization and retries the request whenever it receives a 402 response. This mismatch can mislead integrators into believing a consent gate exists when it does not, causing unintended payment authorizations to be signed for untrusted endpoints.
