other
- Location
SKILL.md:10- Finding
Paid API Request Lacks Explicit Per-Payment User Confirmation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10–30
Vulnerability Type: Unauthorized payment workflow
Risk Level: MediumComplete Relevant Snippet
markdown One-call quantitative momentum read for any CoinGecko coin (bitcoin, ethereum, solana, arbitrum, dogwifcoin, ...). Use it when a user asks "is this coin trending?", "what does RSI say?", or before any momentum-based watchlist screen. Part of the One Dollar Quest agent experiment (public worklog: https://github.com/perria080925-bot/one-dollar-quest). ## EndpointBASE = https://x402.bankr.bot/0xf436ca41bd0a236338bef57adeb4976677513010 GET {BASE}/market-signal?coin=&vs=<usd|eur|mxn> Price: $0.0005 USDC per request (x402 v2, EIP-3009, facilitator api.bankr.bot)
text ## Flow 1. `curl -i "{BASE}/market-signal?coin=ethereum&vs=usd"` 2. Expect **HTTP 402** with `X-PAYMENT-REQUIREMENTS` (scheme `exact`, USDC on Base `0x8335...2913`). 3. Pay with any x402 client (EIP-3009) and retry with `X-PAYMENT` header. 4. Response JSON: price, market cap + rank, 24h volume, change 24h/7d/30d, SMA7/SMA25 trend flag, RSI-14, annualized volatility, data sources + disclaimer.Technical Analysis
The Skill is triggered by ordinary informational requests such as asking whether a coin is trending or requesting RSI information. Its documented workflow then directs the agent to satisfy an HTTP 402 response by authorizing an EIP-3009 USDC payment and retrying the request with an
X-PAYMENTheader.Although the price and endpoint are disclosed in the Skill text, the workflow contains no requirement to present the exact transaction details to the user and obtain explicit approval immediately before payment. It also does not establish a request-count limit, aggregate spending cap, or mandatory confirmation for multi-coin screening.
This creates a trust-boundary violation between authorization to obtain market information and authorization to spend assets from a confi ...[truncated 1564 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit user confirmation immediately before every payment.
- Display the exact amount, asset, network, recipient, endpoint, and number of paid requests in the confirmation prompt.
- Do not treat a request for market information as implicit authorization to spend funds.
- For batch screening, calculate the maximum total charge in advance and require approval of a strict aggregate spending cap.
- Stop processing when the approved request count or spending cap is reached.
- Default to a non-paying preview or dry-run mode that reports the expected charge without creating an EIP-3009 authorization.
- Validate the HTTP 402 payment requirements against the previously approved amount, asset, network, and recipient before signing.
- Require renewed confirmation if any payment term differs from what the user approved.
