T09 · Insecure Skill Coding Practices
- Location
SKILL.md:9- Finding
Remote Payment Metadata Can Trigger Unbounded USDC Authorization
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 9–10
Vulnerability Type: Unvalidated remote payment authorization
Risk Level: HighVulnerable snippet:
markdown ## Step 2: Pay per call with x402 (USDC on Base) Priced endpoints return HTTP 402 with a PAYMENT-REQUIRED header (x402 v2, network eip155:8453, asset USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913). Sign the exact amount with your agent wallet (EIP-3009 transferWithAuthorization) and retry with the PAYMENT-SIGNATURE header. Coinbase CDP facilitator verifies and settles.Technical Analysis
The instructions direct the agent to sign the exact payment amount supplied through a remote HTTP 402 payment challenge. The remote Stock Bloc service controls the
PAYMENT-REQUIREDresponse, but the Skill does not require the agent to validate the requested amount against a trusted local price catalog, enforce a per-call or cumulative spending limit, or obtain explicit operator approval before signing.This crosses a trust boundary from remotely supplied payment metadata into the user’s wallet authority. Although the documented catalog lists expected prices, the payment procedure does not make those values enforceable constraints. A compromised, malicious, or misconfigured endpoint could therefore return an inflated amount that the agent is instructed to authorize.
Attack Path
- The agent requests one of the documented priced Stock Bloc endpoints.
- The remote service returns HTTP 402 with attacker-controlled or incorrectly configured payment metadata.
- The payment challenge specifies an amount greater than the documented endpoint price.
- Following the Skill instructions, the agent signs an EIP-3009
transferWithAuthorizationfor the exact remotely requested amount without mandatory human confirmation or local price validation. - The agent retries the request with the resulting
PAYMENT-SIGNATURE. - The facilitator verifies an ...[truncated 752 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit operator approval before every payment signature, displaying the endpoint, network, asset, amount, and payment destination.
- Validate the requested network and asset against strict local constants: Base (
eip155:8453) and the expected USDC contract. - Maintain a trusted local endpoint-to-price allowlist and reject payment requests whose amount differs from the configured price.
- Enforce configurable per-transaction, per-session, and cumulative daily spending limits.
- Default to refusing payment when any required payment field is missing, malformed, unexpected, or inconsistent with the original request.
- Bind each authorization to the intended request and prevent replay or reuse.
- Provide a dry-run mode that reports the proposed payment without signing it.
- Record approved payments in a local audit log while excluding private keys and reusable authorization material.
