T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:20- Finding
Paid request can be initiated without an explicit per-transaction confirmation requirement
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20–26
Vulnerability Type: Payment authorization without a required user confirmation gate
Risk Level: MediumRelevant snippet:
text BASE = https://x402.bankr.bot/0xf436ca41bd0a236338bef57adeb4976677513010 GET {BASE}/crypto-sentinel Price: $0.003 USDC per request (x402 v2, EIP-3009, facilitator api.bankr.bot)text 1. `curl -i "{BASE}/crypto-sentinel"` 2. Expect **HTTP 402** with `X-PAYMENT-REQUIREMENTS` (scheme `exact`, USDC on Base `0x8335...2913`). 3. Pay with any x402 client (EIP-3009) and retry with `X-PAYMENT` header.Technical Analysis
The Skill instructs the Agent to contact an author-selected endpoint, process its HTTP 402 payment requirements, authorize an EIP-3009 USDC payment, and retry the request with an
X-PAYMENTheader. Although the price is disclosed, the documented execution flow does not require the Agent to obtain explicit user approval immediately before signing or submitting the payment.This crosses a trust and authorization boundary: a request for market information can result in expenditure from a user-controlled wallet. If an Agent follows the workflow using an already configured x402 client, the Skill text permits payment as part of ordinary invocation rather than requiring a separate, informed transaction decision.
No executable scripts or hidden payloads were present in the audited project. The issue is in the operational instructions contained in
SKILL.md, and there is no evidence that the project author intended covert theft or other malicious activity.Attack Path
- A user asks for a BTC, ETH, or SOL perpetual-futures market-regime assessment.
- The Agent loads the Skill and sends a request to the specified endpoint.
- The endpoint responds with HTTP 402 and payment requirements.
- Following the documented flow, the Agent uses an available x402 client to create and submit ...[truncated 930 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit user confirmation immediately before every payment authorization.
- Present the exact amount, token, blockchain network, recipient, endpoint, and maximum fee before requesting approval.
- Do not treat the initial request to obtain market data as implicit authorization to spend funds.
- Make the initial request read-only and stop after receiving HTTP 402 unless the user separately approves payment.
- Prohibit automatic payment retries and repeated charges.
- Validate the payment requirements against fixed limits, including an exact expected asset, Base network identifier, maximum amount, and intended recipient.
- Reject changed or unexpected payment requirements rather than relying solely on values supplied by the remote endpoint.
- Where supported, require the payment helper to receive an explicit confirmation token or approval flag that cannot be inferred from ordinary Skill invocation.
