T09 · Insecure Skill Coding Practices
- Location
SKILL.md:44- Finding
Uncapped Wallet Payment May Execute Without Explicit Human Approval
- Content
View full analysis
``` #### Parameters | Parameter | Required | Description | | ------------------------ | -------- | ----------------------------------------------------- | | `--url` | Yes | The x402-enabled endpoint URL | | `--preferredNetwork` | No | Preferred chain ID for payment (e.g. `8453` for Base) | | `--preferredNetworkName` | No | Preferred chain name (e.g. `base`, `ethereum`) | | `--preferredAsset` | No | Preferred payment asset (e.g. `USDC`) | | `--maxPaymentAmount` | No | Maximum payment amount to authorize | ``` ```markdown ## Flow 1. Check authentication with `fdx status` 2. Check wallet balance with `fdx call getWalletOverview` 3. Call `fdx call getX402Content --url ` to fetch paid content 4. If the payment amount seems high, use `fdx call authorizePayment` first to inspect, then confirm with the human before proceeding 5. Return the fetched content to the human **Important:** Always inform your human about the payment before executing, especially for unfamiliar endpoints or amounts that seem high. Let them confirm they want to proceed. ``` ### Technical Analysis The documented `getX402Content` operation discovers payment requirements, authorizes payment, signs it through the authenticated wallet, and fetches the resource in a single call. However, `--maxPaymentAmount` ...[truncated 2553 chars]- Remediation
View remediation
