Back to skill

Security audit

crypto-momentum-signals

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly a paid crypto market-data lookup, but it tells agents to make x402 USDC payments without requiring explicit user approval or a spending cap.

Install only if you are comfortable with a pay-per-call crypto-data skill. Before use, require the agent or x402 client to show and confirm the exact amount, asset, network, recipient, endpoint, and number of requests, especially for multi-coin screening.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:10
Finding

Paid API Request Lacks Explicit Per-Payment User Confirmation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–30
Vulnerability Type: Unauthorized payment workflow
Risk Level: Medium

Complete Relevant Snippet

markdown
One-call quantitative momentum read for any CoinGecko coin (bitcoin,
ethereum, solana, arbitrum, dogwifcoin, ...). Use it when a user asks "is
this coin trending?", "what does RSI say?", or before any momentum-based
watchlist screen. Part of the One Dollar Quest agent experiment (public
worklog: https://github.com/perria080925-bot/one-dollar-quest).

## Endpoint

BASE = https://x402.bankr.bot/0xf436ca41bd0a236338bef57adeb4976677513010 GET {BASE}/market-signal?coin=&vs=<usd|eur|mxn> Price: $0.0005 USDC per request (x402 v2, EIP-3009, facilitator api.bankr.bot)

text

## Flow

1. `curl -i "{BASE}/market-signal?coin=ethereum&vs=usd"`
2. Expect **HTTP 402** with `X-PAYMENT-REQUIREMENTS` (scheme `exact`, USDC
   on Base `0x8335...2913`).
3. Pay with any x402 client (EIP-3009) and retry with `X-PAYMENT` header.
4. Response JSON: price, market cap + rank, 24h volume, change 24h/7d/30d,
   SMA7/SMA25 trend flag, RSI-14, annualized volatility, data sources +
   disclaimer.

Technical Analysis

The Skill is triggered by ordinary informational requests such as asking whether a coin is trending or requesting RSI information. Its documented workflow then directs the agent to satisfy an HTTP 402 response by authorizing an EIP-3009 USDC payment and retrying the request with an X-PAYMENT header.

Although the price and endpoint are disclosed in the Skill text, the workflow contains no requirement to present the exact transaction details to the user and obtain explicit approval immediately before payment. It also does not establish a request-count limit, aggregate spending cap, or mandatory confirmation for multi-coin screening.

This creates a trust-boundary violation between authorization to obtain market information and authorization to spend assets from a confi ...[truncated 1564 chars]

Remediation
View remediation

Remediation Suggestions

  • Require explicit user confirmation immediately before every payment.
  • Display the exact amount, asset, network, recipient, endpoint, and number of paid requests in the confirmation prompt.
  • Do not treat a request for market information as implicit authorization to spend funds.
  • For batch screening, calculate the maximum total charge in advance and require approval of a strict aggregate spending cap.
  • Stop processing when the approved request count or spending cap is reached.
  • Default to a non-paying preview or dry-run mode that reports the expected charge without creating an EIP-3009 authorization.
  • Validate the HTTP 402 payment requirements against the previously approved amount, asset, network, and recipient before signing.
  • Require renewed confirmation if any payment term differs from what the user approved.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.