T09 · Insecure Skill Coding Practices
- Location
scripts/guarded-buy.cjs- Finding
Untrusted XRPL endpoint can inflate the signed transaction fee beyond all spending limits
- Content
View full analysis
Attacker control point
The remote WebSocket service influences autofilled transaction fields, including Fee.
Impact
A hostile endpoint can cause the wallet to authorize an excessive XRP transaction fee. MAX_DROPS and DAILY_BUDGET_DROPS only cover Amount, and recordSpend records only gated.drops, so the advertised per-request and daily limits do not constrain this loss.
