Back to skill

Security audit

x402 pay

Security checks across malware telemetry and agentic risk

Overview

This skill is a real-money x402 payment helper with sensitive wallet access, but its artifacts disclose that purpose and include approval and spend-cap safeguards.

Install only if you want an agent to help spend or route real crypto funds. Use a dedicated low-balance wallet, keep wallet-level spend limits and allowlists enabled, review every command, price, recipient, refund destination, and transaction before approving, and avoid placing broad private keys in generic env vars unless you intend this skill to use them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The document explicitly instructs the agent to inspect its system prompt, agent config, environment variables, and local project files to discover wallet credentials and payment capabilities. In an agent setting, this is sensitive-context discovery that can expose secrets unrelated to the user’s request and can lead to unauthorized use of private keys or managed-wallet credentials; the x402 payment context makes this more dangerous because the discovered credentials are intended to authorize real spending.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The instructions tell the agent to probe environment variables and config for wallet credentials across multiple providers, effectively encouraging access to highly sensitive secrets without a clear authorization boundary or privacy warning. Although the text includes a caution about generic private-key variables, it still normalizes credential discovery and potential use of those credentials for live payments, which can result in secret exposure or unintended fund movement.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.