Back to skill

Security audit

Pay For Service

Security checks for vulnerabilities and agentic risk

Overview

This skill is clearly meant for paid x402 access, but its normal flow can spend wallet funds through an automatic one-step payment command without a mandatory cap or precise approval step.

Review before installing. This skill should only be used if you are comfortable letting an agent operate an authenticated wallet for paid x402 endpoints. Require the agent to show the exact endpoint, amount, asset, network, recipient, and cap before every payment, and avoid using it with unfamiliar URLs unless you have wallet-level limits in place.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:44
Finding

Uncapped Wallet Payment May Execute Without Explicit Human Approval

Content
View full analysis
``` #### Parameters | Parameter | Required | Description | | ------------------------ | -------- | ----------------------------------------------------- | | `--url` | Yes | The x402-enabled endpoint URL | | `--preferredNetwork` | No | Preferred chain ID for payment (e.g. `8453` for Base) | | `--preferredNetworkName` | No | Preferred chain name (e.g. `base`, `ethereum`) | | `--preferredAsset` | No | Preferred payment asset (e.g. `USDC`) | | `--maxPaymentAmount` | No | Maximum payment amount to authorize | ``` ```markdown ## Flow 1. Check authentication with `fdx status` 2. Check wallet balance with `fdx call getWalletOverview` 3. Call `fdx call getX402Content --url ` to fetch paid content 4. If the payment amount seems high, use `fdx call authorizePayment` first to inspect, then confirm with the human before proceeding 5. Return the fetched content to the human **Important:** Always inform your human about the payment before executing, especially for unfamiliar endpoints or amounts that seem high. Let them confirm they want to proceed. ``` ### Technical Analysis The documented `getX402Content` operation discovers payment requirements, authorizes payment, signs it through the authenticated wallet, and fetches the resource in a single call. However, `--maxPaymentAmount` ...[truncated 2553 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is broad enough to trigger on common requests like 'fetch this resource' or 'access content,' which could cause the agent to invoke a payment-capable skill in situations where the user did not clearly intend to spend funds. Because this skill can authorize and execute paid requests, over-broad routing increases the risk of unintended payments and data transmission to external endpoints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

bash
# Fetch content from a paid API (auto-discovers requirements and pays)
fdx call getX402Content \
  --url https://api.example.com/premium/data

# Prefer paying with USDC on Base
fdx call getX402Content \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

bash
# Fetch content from a paid API (auto-discovers requirements and pays)
fdx call getX402Content \
  --url https://api.example.com/premium/data

# Prefer paying with USDC on Base
fdx call getX402Content \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
# Fetch content from a paid API (auto-discovers requirements and pays)
fdx call getX402Content \
  --url https://api.example.com/premium/data

# Prefer paying with USDC on Base
fdx call getX402Content \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

bash
# Fetch content from a paid API (auto-discovers requirements and pays)
fdx call getX402Content \
  --url https://api.example.com/premium/data

# Prefer paying with USDC on Base
fdx call getX402Content \

Static analysis

No suspicious patterns detected.