T09 · Insecure Skill Coding Practices
- Location
main.py:18- Finding
Payment Verification Bypass Through an Unvalidated x402 Header
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This paid lottery skill is not outright malware, but it materially overstates its analysis and has weak payment and dependency controls that users should review before installing.
Review this carefully before installing or paying for it. The service presents itself as historical-data lottery analysis, but the inspected code appears to return simulated random picks. Treat any recommendations as entertainment only, and do not rely on the listed x402 payment flow as proof that the backend enforces payment correctly. The publisher should also pin dependencies and make the paid-service description match the implementation.
main.py:18Payment Verification Bypass Through an Unvalidated x402 Header
requirements.txt:1Unpinned Flask Dependency Creates Non-Reproducible and Unsafe Deployments
scripts/lottery_analysis.py:13Paid Historical Analysis Claims Are Implemented as Random Sampling from Hard-Coded Pools
Without declared permissions the skill's intent is opaque and cannot be validated.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
@app.route('/ssq')
def ssq():
try:
result = subprocess.run(
[sys.executable, "scripts/lottery_analysis.py", "ssq"],
capture_output=True,
text=True,
The manifest describes a lottery analysis and number recommendation skill, but the implementation invokes a separate Python process via subprocess.run to serve requests. Executing subprocesses is a powerful capability not inherently justified by the stated purpose, which could be implemented directly in-process.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
@app.route('/dlt')
def dlt():
try:
result = subprocess.run(
[sys.executable, "scripts/lottery_analysis.py", "dlt"],
capture_output=True,
text=True,
Like the /ssq route, the /dlt route launches a Python subprocess to perform analysis. For a skill presented as historical-data lottery recommendation, this process-execution capability exceeds the obvious functional need expressed in the manifest.
The skill description promises historical-data-based intelligent lottery analysis, but the implementation only uses hardcoded lists and random selection. This is a deceptive capability mismatch that can mislead users into trusting recommendations as data-driven when they are effectively arbitrary, creating integrity and consumer-trust risk rather than a traditional code-execution issue.
The dependency specification uses an unpinned package name only, which allows different Flask versions to be installed over time. This creates a supply-chain and reproducibility risk because a vulnerable or breaking release could be resolved during installation without review.
flask
Because Flask is not pinned to a specific version, it is impossible to verify from this manifest whether the installed release includes known security fixes. In practice this means deployments may resolve to a version affected by published Flask advisories, leaving the application exposed to known issues depending on runtime behavior.
The inline comment explicitly says the logic is a 'historical data analysis simulation,' which conflicts with the external description implying genuine historical analysis. In this skill context, that discrepancy increases confidence that the feature is being overstated and may misrepresent its reliability to users.
The manifest description uses Chinese-only text ("Rich彩票分析API - x402付费版本") and the endpoint descriptions are also Chinese-only, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking locale. This is a natural-language locale policy concern because the skill appears to enforce a specific language without opt-in or justification.
No suspicious patterns detected.