Okx 402 Payment

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed crypto payment helper that requires user confirmation before wallet checks or signing, but payments and private-key fallback remain sensitive.

Install only if you intend to let an agent assist with crypto-based HTTP 402 payments. Verify the network, token, amount, recipient, channel_id, deposit/top-up amount, and signing method before approving, and prefer a limited-purpose wallet over a primary wallet.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list is unusually broad and includes generic phrases like '402', 'payment required', and several session-management terms. In an agent environment, this can cause the skill to activate in contexts where the user did not intend to perform a payment flow, increasing the chance of unnecessary HTTP requests, wallet checks, protocol handling, or socially engineered payment prompts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal