Back to skill

Security audit

Pay With Any Token

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent with crypto payment automation, but it asks for sensitive wallet authority and includes unsafe automatic payment, installer, dependency, and bridge-recipient instructions that users should review carefully.

Install only if you are comfortable with a skill that can guide real crypto payments, swaps, approvals, and bridges. Use a dedicated low-balance wallet, avoid production private keys in shell history or environment variables, verify every amount/token/recipient/chain before signing, and avoid the automatic payment or autoSwap examples unless you have strict spending limits and trust the endpoint.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:29
Finding

Mutable Remote Installer Is Downloaded and Executed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/credential-construction.md:20
Finding

Unpinned NPM Dependencies Are Loaded Into a Private-Key-Bearing Process

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/credential-construction.md:25
Finding

Automatic Payment and Swap Modes Bypass Explicit User Confirmation Gates

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/trading-api-flows.md:330
Finding

Bridge Execution Uses the Source Wallet Instead of the Required Tempo Wallet Recipient

Content
View full analysis
**REQUIRED:** Use `AskUserQuestion` before submitting the bridge transaction. > Show the user: > > - Amount: `$(format_token_amount "$BRIDGE_AMOUNT" "$USDC_DECIMALS")` USDC on Base (chain 8453) > - Destination: `$BRIDGE_TOKEN_OUT` (USDC.e) on Tempo (chain 4217) > - Bridge fee: `$BRIDGE_FEE` > - Estimated time: `$BRIDGE_ETA` > - Recipient: `$WALLET_ADDRESS` > > Do not proceed until the user confirms. ``` The execution request also supplies `WALLET_ADDRESS`: ```bash BRIDGE_RESPONSE=$(curl -s "https://trade-api.gateway.uniswap.org/v1/swap" \ -H "Content-Type: application/json" \ -H "x-api-key: $UNISWAP_API_KEY" \ --data "$(jq -n \ --argjson quote "$BRIDGE_QUOTE" \ --arg walletAddress "$WALLET_ADDRESS" \ '{quote: $quote.quote, walletAddress: $walletAddress}')") ``` Arrival is then checked against the same source wallet: ```bash USDC_E_ON_TEMPO=$(cast call "$BRIDGE_TOKEN_OUT" \ "balanceOf(address)(uint256)" "$WALLET_ADDRESS" \ --rpc-url "$TEMPO_RPC_URL" 2>/dev/null || echo "0") ``` This conflicts with the declared requirement in `SKILL.md`, lines 254-256: ```text The bridge recipient must be `TEMPO_WALLET_ADDRESS` (from `tempo wallet -t whoami`), NOT `WALLET_ADDRESS` (your source ERC-20 wallet). ``` ### Technical Analysis The declared workflow has two distinct identities: - `WALLET_ADDRESS`: the source ERC-20 wallet used to fund the transaction. - `TEMPO_WALLET_ADDRESS`: the destination wallet used by the Tempo CLI to make the HTTP 402 payment. The bridge implementation displays, submits, and polls `WALLET_ADDRESS` instead of `TEMPO_WALLET_ADDRESS`. As a result, the code does not implement its own stated d ...[truncated 1877 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

md
> [references/trading-api-flows.md](references/trading-api-flows.md#phase-4a--swap-on-source-chain)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

md
> [references/trading-api-flows.md](references/trading-api-flows.md#phase-4a--swap-on-source-chain)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 289)May include surrounding context.

md
> [references/credential-construction.md](references/credential-construction.md#phase-6x--x402-payment)

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
API access", "HTTP 402", "x402", "machine payment protocol",
  "pay-with-any-token", "use tempo", "tempo request", or "tempo wallet".
allowed-tools: Read, Glob, Grep, Bash(curl:*), Bash(jq:*), Bash(cast:*), Bash(tempo:*), Bash(*/.local/bin/tempo:*), WebFetch, AskUserQuestion
model: opus
license: MIT
metadata:
  author: uniswap

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The automatic MPP example wires a wallet-backed payment method into a global fetch interception flow and immediately retries a protected resource without any user confirmation in that example. In a payment skill, this is dangerous because a 402 challenge can trigger spending of wallet assets or autoswaps based on server-provided payment terms, making silent or surprising value transfer more likely if the endpoint is untrusted or the challenge is malicious.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/credential-construction.md (reported line 311)May include surrounding context.

md
### Interpreting the response

| Status | Meaning                                                 | Action                                                                                       |
| ------ | ------------------------------------------------------- | -------------------------------------------------------------------------------------------- |
| 200    | Payment accepted — resource delivered                   | Display body; decode receipt with `echo "$X402_PAYMENT_RESPONSE" \| base64 --decode \| jq .` |
| 402    | Payment rejected (bad signature, expired, wrong amount) | Check domain name/version, validBefore, and amount                                           |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/trading-api-flows.md (reported line 63)May include surrounding context.

md
--argjson chainId "$SOURCE_CHAIN_ID" \
  '{walletAddress: $wallet, token: $token, amount: $amount, chainId: $chainId}')

curl -s -X POST https://trade-api.gateway.uniswap.org/v1/check_approval \
  -H "Content-Type: application/json" \
  -H "x-api-key: $UNISWAP_API_KEY" \
  -H "x-universal-router-version: 2.0" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/trading-api-flows.md (reported line 183)May include surrounding context.

md
SWAP_BODY=$(echo "$CLEAN_QUOTE" | jq --arg sig "$PERMIT2_SIGNATURE" '. + {signature: $sig}')
fi

curl -s -X POST https://trade-api.gateway.uniswap.org/v1/swap \
  -H "Content-Type: application/json" \
  -H "x-api-key: $UNISWAP_API_KEY" \
  -H "x-universal-router-version: 2.0" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation instructs users to pass a raw private key directly on the command line for live transaction submission. Command-line secrets are commonly exposed through shell history, process listings, logs, CI output, and shared terminals, which can lead to wallet compromise and irreversible fund theft.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/trading-api-flows.md (reported line 268)May include surrounding context.

md
BRIDGE_TOKEN_OUT="0x20C000000000000000000000b9537d11c60E8b50"   # USDC.e on Tempo
BRIDGE_AMOUNT="$USDC_E_AMOUNT_NEEDED"

APPROVAL=$(curl -s "https://trade-api.gateway.uniswap.org/v1/check_approval" \
  -H "Content-Type: application/json" \
  -H "x-api-key: $UNISWAP_API_KEY" \
  --data "$(jq -n \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/trading-api-flows.md (reported line 304)May include surrounding context.

Step 4B-2 — Get bridge quote (EXACT_OUTPUT)

bash
BRIDGE_QUOTE=$(curl -s "https://trade-api.gateway.uniswap.org/v1/quote" \
  -H "Content-Type: application/json" \
  -H "x-api-key: $UNISWAP_API_KEY" \
  --data "$(jq -n \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/trading-api-flows.md (reported line 344)May include surrounding context.

Step 4B-3 — Execute the bridge

bash
BRIDGE_RESPONSE=$(curl -s "https://trade-api.gateway.uniswap.org/v1/swap" \
  -H "Content-Type: application/json" \
  -H "x-api-key: $UNISWAP_API_KEY" \
  --data "$(jq -n \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This bridge execution example again uses a plaintext private key in a shell command to submit a real on-chain transaction. In the context of a payment/bridging skill that moves funds across chains, compromise of that key can immediately expose the user's wallet and any bridged assets to theft.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Earlier in the file, the documentation explicitly states that tokenInChainId and tokenOutChainId must be integers, not strings, but Step 4B-2 constructs the bridge quote body with --arg tokenInChainId "8453" and --arg tokenOutChainId "4217", which produces string values in JSON. This is a direct contradiction between the file's own guidance and the code example shown for the bridge flow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.