Back to skill

Security audit

crypto-funding-heatmap

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed paid crypto-data skill, but it instructs agents to make wallet-based payments without clear confirmation or spending limits.

Review this before installing if your agent has access to an x402 client or wallet signer. Only use it with explicit per-request approval, verify the charge is $0.004 USDC on Base to the expected endpoint/payment requirements, and set a small session budget or dry-run mode where possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:24
Finding

Paid API Requests Lack Mandatory Transaction Confirmation and Spending Limits

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24–28
Vulnerability Type: Unconfirmed financial transaction
Risk Level: Medium

Vulnerable instructions:

markdown
## Flow

1. `curl -i "{BASE}/funding-heatmap"`
2. Expect **HTTP 402** with `X-PAYMENT-REQUIREMENTS` (scheme `exact`, USDC
   on Base `0x8335...2913`).
3. Pay with any x402 client (EIP-3009) and retry with `X-PAYMENT` header.

Technical Analysis

The documented workflow directs the Agent to respond to an HTTP 402 challenge by authorizing an EIP-3009 USDC payment and retrying the request. It does not require explicit user confirmation immediately before payment, validation that the returned payment requirements match the advertised price and recipient, or enforcement of per-request and cumulative spending limits.

The Skill is intended to be invoked for routine market-data questions. Consequently, an ordinary analytics request can cross the trust boundary from read-only data retrieval into use of the user’s wallet authority. Although the description advertises a price of $0.004 USDC per call, the workflow does not technically enforce that amount or limit the number of paid calls.

No evidence demonstrates covert theft or malicious intent. This is therefore classified as suspicious high-risk behavior rather than a malicious payment mechanism.

Attack Path

  1. A user invokes the Skill to obtain a perpetual-futures funding-rate heatmap.
  2. The Agent sends the initial request to the endpoint specified by the Skill author.
  3. The endpoint returns HTTP 402 payment requirements.
  4. Following the Skill instructions, the Agent uses an x402 client with access to the user’s wallet authority to authorize payment.
  5. The Agent retries the request using the resulting X-PAYMENT header without a documented mandatory confirmation step.
  6. Repeated invocations or automated analysis workflows can produce cumulative charges without a def ...[truncated 684 chars]
Remediation
View remediation

Remediation Suggestions

  • Require explicit user confirmation immediately before each payment authorization.
  • Display the network, token contract, recipient, exact amount, endpoint, and cumulative session spend in the confirmation prompt.
  • Validate the HTTP 402 payment requirements against fixed expectations, including the advertised $0.004 USDC maximum, Base network, approved USDC contract, and intended recipient.
  • Reject requirements containing a different amount, asset, network, or recipient instead of silently proceeding.
  • Apply default-deny per-request and cumulative spending caps.
  • Prevent automatic paid retries and unbounded loops; permit only one payment attempt for each confirmed request.
  • Offer a read-only or dry-run mode that returns payment requirements without signing or submitting a transaction.
  • Keep wallet signing isolated from endpoint-provided data and grant only the minimum authorization needed for the confirmed payment.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.