T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:79- Finding
Blind Signing and Submission of Unverified Remote Payment Authorization
- Content
View full analysis
**Trust model**: the buyer signs the seller's challenge as-is. Verifying that the challenge matches what the buyer agreed to pay is the **upstream caller's responsibility**: the user (or the upstream skill) MUST cross-check the seller's `paymentId` / `deliveries.url` against their out-of-band agreement (chat, task spec, prior negotiation) **before** calling this skill. Once the skill is invoked, it will sign the on-server challenge. #### Step 1 — Sign and Submit The skill does not run its own preview / yes-no gate; trust is delegated to the upstream caller (see the trust-model note above). Shell out directly: ```bash onchainos payment a2a-pay pay --payment-id ``` The CLI fetches the on-server challenge, TEE-signs the EIP-3009 authorization, and submits the credential. ``` ### Technical Analysis The Skill requires only a seller-issued `paymentId` to initiate payment. The material authorization fields—including the amount, currency, recipient, validity period, and potentially network or token-contract identity—are subsequently obtained from a remote server. The Skill explicitly directs the Agent to sign those remotely supplied terms without presenting them to the buyer or validating them against independently supplied expectations. Checking a `paymentId` or delivery URL out of band does not prove that the corresponding server-side challenge contains the agreed payment terms. The Skill has no local transaction preview, amount ceiling, recipient comparison, token-contract allowlist, chain verification, or fresh confirmation immediately before signing. ...[truncated 1978 chars]- Remediation
View remediation
