T09 · Insecure Skill Coding Practices
- Location
SKILL.md:548- Finding
Unbounded Payment of Attacker-Controlled L402 Invoices
- Content
View full analysis
s.name === "amount"); const amountSats = Math.ceil(Number(amountSection.value) / 1000); const payResult = await this.#wallet.payLightningInvoice({ invoice, maxFeeSats }); let preimage = payResult.paymentPreimage; // Poll if needed if (!preimage && payResult.id) { for (let i = 0; i < 15; i++) { await new Promise((r) => setTimeout(r, 500)); const status = await this.#wallet.getLightningSendRequest(payResult.id); if (status?.paymentPreimage) { preimage = status.paymentPreimage; break; } if (status?.status === "LIGHTNING_PAYMENT_FAILED") throw new Error("Payment failed"); } } if (!preimage) throw new Error("No preimage received"); // Retry with auth ...[truncated 2873 chars]- Remediation
View remediation
maxPaymentSats) { throw new Error( `L402 invoice amount ${amountSats} exceeds limit ${maxPaymentSats}`, ); } ``` 2. Require explicit user approval showing the destination, invoice amount, routing-fee cap, and total maximum cost unless a separately configured policy authorizes that exact domain and amount. 3. Maintain per-transaction, per-domain, and cumulative daily spending limits outside the model-controlled request parameters. 4. Permit only HTTPS destinations and enforce an allowlist of trusted hostnames. Reject embedded credentials, nonstandard schemes, private-network addresses where unnecessary, and unexpected ports. 5. Disable automatic redirects or validate every redirect target. Ensure the final endpoint receiving the macaroon and preimage is the same authorized origin that issued the challenge. 6. Validate the decoded invoice thoroughly, including amount presence, amount bounds, expiry, network, and expected payee where available. 7. Preview the L402 cost before payment and bind the approved challenge to the subsequent payment operation to prevent challenge substitution. 8. Use the documented scoped wallet proxy for production so that the agent never receives unrestricted mnemonic access and server-side controls can enforce revocable credentials, roles, audit logging, and spending caps. ]]>
