T08 · Insecure Dependencies
- Location
SKILL.md:19- Finding
Unpinned Third-Party Dependencies Create Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Dhali x402 payment skill is coherent, but its consumer examples can automatically fund a payment channel without a clear user approval step or spending limit.
Install only if you are comfortable reviewing and modifying the examples before use. Treat the deposit calls as real financial operations, default to test networks, add explicit confirmation and spend caps, verify currency units and destinations, and pin dependencies in an isolated environment before connecting any funded wallet.
SKILL.md:19Unpinned Third-Party Dependencies Create Supply-Chain Risk
SKILL.md:260Payment Channels Are Funded Automatically Without Explicit Authorization or Spending Controls
The consumer examples automatically create payment claims and, on missing channels, trigger deposit(1000000) without any confirmation, spending limits, or warning about real financial consequences. In an agent skill context, this can cause unintended autonomous fund movement and repeated payment attempts if an agent follows the example against live services.
Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.
# manager = DhaliChannelManager.xrpl(wallet, rpc_client, currency)
# 2. Call the server and catch 402
response = requests.get("http://127.0.0.1:8001/data")
payment_requirement = response.headers.get("payment-required")
if response.status_code == 402 and payment_requirement:
Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.
x402_signature = wrap_as_x402_payment_payload(claim, payment_requirement)
# 5. Send Request with Signature
paid_response = requests.get(
"http://127.0.0.1:8001/data",
headers={"Payment-Signature": x402_signature}
)
Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.
async function callPaidAPI() {
// 1. Call server
let response = await fetch("http://127.0.0.1:8001/data");
const paymentRequirement = response.headers.get("payment-required");
if (response.status === 402 && paymentRequirement) {
Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.
async function callPaidAPI() {
// 1. Call server
let response = await fetch("http://127.0.0.1:8001/data");
const paymentRequirement = response.headers.get("payment-required");
if (response.status === 402 && paymentRequirement) {
No suspicious patterns detected.