x402 Agent Marketplace

Security checks across malware telemetry and agentic risk

Overview

This skill asks users to send SOL to a fixed wallet and run marketplace files that are not included in the package.

Review carefully before installing. Do not send SOL or run server files obtained outside this package unless you independently verify the operator, recipient wallet, source code, dependency pins, payment verification, service delivery, and refund or dispute terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs users to send irreversible SOL payments to a fixed wallet address without any visible warning about scam risk, payment irreversibility, amount verification, or the consequences of mistyped addresses/signatures. In a marketplace/payment skill, this omission materially increases the chance of user financial loss and social-engineering abuse because users are being asked to transfer cryptocurrency before receiving service.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal