T09 · Insecure Skill Coding Practices
- Location
protocols/x402.md:121- Finding
Shell Command Injection Through Untrusted x402 Payment Requirements
- Content
View full analysis
' ``` The same unsafe argument construction is documented for local signing: ```bash onchainos payment eip3009-sign \ --accepts '' ``` ### Technical Analysis The `decoded.accepts` array comes from an untrusted HTTP 402 response. For x402 v2, it is decoded from the merchant-controlled `PAYMENT-REQUIRED` header; for v1, it comes from the response body. The playbook instructs the Agent to serialize this untrusted object and interpolate it inside a single-quoted shell argument. JSON strings may legally contain apostrophes. If an Agent or command tool executes the documented command through a shell, an attacker-controlled apostrophe can terminate the quoted argument. Shell operators embedded after it can then be interpreted as commands. JSON serialization does not provide shell escaping. Base64 decoding the original response also does not establish trust or integrity. ### Attack Path 1. A user asks the Agent to access an attacker-controlled or compromised payment-gated endpoint. 2. The endpoint returns HTTP 402 with a crafted `PAYMENT-REQUIRED` header or x402 JSON body. 3. An element of `accepts` contains an apostrophe followed by shell syntax in a merchant-controlled string field. 4. The Agent displays payment information and the user confirms the payment. 5. The Agent constructs the documented `onchainos payment x402-pay --accepts '...'` command. 6. If the command is passed through a shell, the crafted apostrophe closes the argumen ...[truncated 618 chars]- Remediation
View remediation
