T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:29- Finding
Mutable Remote Installer Is Downloaded and Executed Without Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly coherent with crypto payment automation, but it asks for sensitive wallet authority and includes unsafe automatic payment, installer, dependency, and bridge-recipient instructions that users should review carefully.
Install only if you are comfortable with a skill that can guide real crypto payments, swaps, approvals, and bridges. Use a dedicated low-balance wallet, avoid production private keys in shell history or environment variables, verify every amount/token/recipient/chain before signing, and avoid the automatic payment or autoSwap examples unless you have strict spending limits and trust the endpoint.
SKILL.md:29Mutable Remote Installer Is Downloaded and Executed Without Integrity Verification
references/credential-construction.md:20Unpinned NPM Dependencies Are Loaded Into a Private-Key-Bearing Process
references/credential-construction.md:25Automatic Payment and Swap Modes Bypass Explicit User Confirmation Gates
references/trading-api-flows.md:330Bridge Execution Uses the Source Wallet Instead of the Required Tempo Wallet Recipient
Referenced artifact was not completely inspected
> [references/trading-api-flows.md](references/trading-api-flows.md#phase-4a--swap-on-source-chain)
Referenced artifact was not completely inspected
> [references/trading-api-flows.md](references/trading-api-flows.md#phase-4a--swap-on-source-chain)
Referenced artifact was not completely inspected
> [references/credential-construction.md](references/credential-construction.md#phase-6x--x402-payment)
Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.
API access", "HTTP 402", "x402", "machine payment protocol",
"pay-with-any-token", "use tempo", "tempo request", or "tempo wallet".
allowed-tools: Read, Glob, Grep, Bash(curl:*), Bash(jq:*), Bash(cast:*), Bash(tempo:*), Bash(*/.local/bin/tempo:*), WebFetch, AskUserQuestion
model: opus
license: MIT
metadata:
author: uniswap
The automatic MPP example wires a wallet-backed payment method into a global fetch interception flow and immediately retries a protected resource without any user confirmation in that example. In a payment skill, this is dangerous because a 402 challenge can trigger spending of wallet assets or autoswaps based on server-provided payment terms, making silent or surprising value transfer more likely if the endpoint is untrusted or the challenge is malicious.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
### Interpreting the response
| Status | Meaning | Action |
| ------ | ------------------------------------------------------- | -------------------------------------------------------------------------------------------- |
| 200 | Payment accepted — resource delivered | Display body; decode receipt with `echo "$X402_PAYMENT_RESPONSE" \| base64 --decode \| jq .` |
| 402 | Payment rejected (bad signature, expired, wrong amount) | Check domain name/version, validBefore, and amount |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
--argjson chainId "$SOURCE_CHAIN_ID" \
'{walletAddress: $wallet, token: $token, amount: $amount, chainId: $chainId}')
curl -s -X POST https://trade-api.gateway.uniswap.org/v1/check_approval \
-H "Content-Type: application/json" \
-H "x-api-key: $UNISWAP_API_KEY" \
-H "x-universal-router-version: 2.0" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SWAP_BODY=$(echo "$CLEAN_QUOTE" | jq --arg sig "$PERMIT2_SIGNATURE" '. + {signature: $sig}')
fi
curl -s -X POST https://trade-api.gateway.uniswap.org/v1/swap \
-H "Content-Type: application/json" \
-H "x-api-key: $UNISWAP_API_KEY" \
-H "x-universal-router-version: 2.0" \
The documentation instructs users to pass a raw private key directly on the command line for live transaction submission. Command-line secrets are commonly exposed through shell history, process listings, logs, CI output, and shared terminals, which can lead to wallet compromise and irreversible fund theft.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
BRIDGE_TOKEN_OUT="0x20C000000000000000000000b9537d11c60E8b50" # USDC.e on Tempo
BRIDGE_AMOUNT="$USDC_E_AMOUNT_NEEDED"
APPROVAL=$(curl -s "https://trade-api.gateway.uniswap.org/v1/check_approval" \
-H "Content-Type: application/json" \
-H "x-api-key: $UNISWAP_API_KEY" \
--data "$(jq -n \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
BRIDGE_QUOTE=$(curl -s "https://trade-api.gateway.uniswap.org/v1/quote" \
-H "Content-Type: application/json" \
-H "x-api-key: $UNISWAP_API_KEY" \
--data "$(jq -n \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
BRIDGE_RESPONSE=$(curl -s "https://trade-api.gateway.uniswap.org/v1/swap" \
-H "Content-Type: application/json" \
-H "x-api-key: $UNISWAP_API_KEY" \
--data "$(jq -n \
This bridge execution example again uses a plaintext private key in a shell command to submit a real on-chain transaction. In the context of a payment/bridging skill that moves funds across chains, compromise of that key can immediately expose the user's wallet and any bridged assets to theft.
Earlier in the file, the documentation explicitly states that tokenInChainId and tokenOutChainId must be integers, not strings, but Step 4B-2 constructs the bridge quote body with --arg tokenInChainId "8453" and --arg tokenOutChainId "4217", which produces string values in JSON. This is a direct contradiction between the file's own guidance and the code example shown for the bridge flow.
No suspicious patterns detected.