Back to skill

Security audit

perp-market-regime

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed pay-per-call market-data helper with no bundled executable code, but users should approve each payment before use.

Before installing, be comfortable with a $0.003 USDC charge per request. Configure your agent or x402 client to stop after the HTTP 402 response and ask you before signing or submitting each payment, especially for repeated calls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:20
Finding

Paid request can be initiated without an explicit per-transaction confirmation requirement

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–26
Vulnerability Type: Payment authorization without a required user confirmation gate
Risk Level: Medium

Relevant snippet:

text
BASE = https://x402.bankr.bot/0xf436ca41bd0a236338bef57adeb4976677513010
GET {BASE}/crypto-sentinel
Price: $0.003 USDC per request (x402 v2, EIP-3009, facilitator api.bankr.bot)
text
1. `curl -i "{BASE}/crypto-sentinel"`
2. Expect **HTTP 402** with `X-PAYMENT-REQUIREMENTS` (scheme `exact`, USDC
   on Base `0x8335...2913`).
3. Pay with any x402 client (EIP-3009) and retry with `X-PAYMENT` header.

Technical Analysis

The Skill instructs the Agent to contact an author-selected endpoint, process its HTTP 402 payment requirements, authorize an EIP-3009 USDC payment, and retry the request with an X-PAYMENT header. Although the price is disclosed, the documented execution flow does not require the Agent to obtain explicit user approval immediately before signing or submitting the payment.

This crosses a trust and authorization boundary: a request for market information can result in expenditure from a user-controlled wallet. If an Agent follows the workflow using an already configured x402 client, the Skill text permits payment as part of ordinary invocation rather than requiring a separate, informed transaction decision.

No executable scripts or hidden payloads were present in the audited project. The issue is in the operational instructions contained in SKILL.md, and there is no evidence that the project author intended covert theft or other malicious activity.

Attack Path

  1. A user asks for a BTC, ETH, or SOL perpetual-futures market-regime assessment.
  2. The Agent loads the Skill and sends a request to the specified endpoint.
  3. The endpoint responds with HTTP 402 and payment requirements.
  4. Following the documented flow, the Agent uses an available x402 client to create and submit ...[truncated 930 chars]
Remediation
View remediation

Remediation Suggestions

  • Require explicit user confirmation immediately before every payment authorization.
  • Present the exact amount, token, blockchain network, recipient, endpoint, and maximum fee before requesting approval.
  • Do not treat the initial request to obtain market data as implicit authorization to spend funds.
  • Make the initial request read-only and stop after receiving HTTP 402 unless the user separately approves payment.
  • Prohibit automatic payment retries and repeated charges.
  • Validate the payment requirements against fixed limits, including an exact expected asset, Base network identifier, maximum amount, and intended recipient.
  • Reject changed or unexpected payment requirements rather than relying solely on values supplied by the remote endpoint.
  • Where supported, require the payment helper to receive an explicit confirmation token or approval flag that cannot be inferred from ordinary Skill invocation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.