Back to skill

Security audit

Simmer X402

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly designed to make real crypto payments, but its payment cap and configuration controls are not strong enough for autonomous use without review.

Install only with a dedicated, minimally funded hot wallet. Treat every fetch URL, POST body, and imported helper call as able to spend funds. Do not rely on environment variables alone for lower limits unless the config precedence is fixed, and prefer a reviewed version with fail-closed payment validation, explicit allowlists, exact dependency pins, and user confirmation or enforced budgets before real payments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
x402_cli.py:212
Finding

Automatic Payment Proceeds When Local Spending-Limit Validation Is Incomplete

Content
View full analysis
max_payment: raise Exception( f"Payment ${max_amount_usd:.2f} exceeds limit ${max_payment:.2f}. " f"Use --max to increase." ) except (json.JSONDecodeError, KeyError, ValueError, IndexError): pass # Can't parse payment info, let x402 SDK handle it # Use v2 SDK — handles 402 payment automatically httpx_client = _get_x402_httpx_client() ``` ### Technical Analysis The local payment-limit check is not fail-closed. Validation only examines the first element of the response body's `accepts` array and assumes that `maxAmountRequired` is expressed in six-decimal USDC atomic units. If the payment requirements are malformed, header-only, use an unexpected schema, contain an invalid amount, or otherwise raise one of the caught parsing exceptions, the code suppresses the error and proceeds to create an x402-enabled client. That client has access to a signer backed by the operator's private key and automatically handles the payment. The code also does not demonstrate that the validated `accepts[0]` option is the same payment option ultimately selected by the SDK. Consequently, validating only the first option does not reliably constrain the transaction selected by the payment implementation. Additionally, this expression does not treat zero as an explicit limit: ```python max_payment = max_usd or _config["max_payment_usd"] ` ...[truncated 2104 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
x402_cli.py:35
Finding

Bundled Configuration Silently Overrides Environment-Based Safety Controls

Content
View full analysis
env vars > defaults.""" config_path = Path(__file__).parent / "config.json" file_cfg = {} if config_path.exists(): try: with open(config_path) as f: file_cfg = json.load(f) except (json.JSONDecodeError, IOError): pass return { "max_payment_usd": file_cfg.get("max_payment_usd") or float(os.environ.get("X402_MAX_PAYMENT_USD", "10.00")), "network": file_cfg.get("network") or os.environ.get("X402_NETWORK", "mainnet"), } ``` The repository includes the following file at `config.json:1-4`: ```json { "max_payment_usd": 10.00, "network": "mainnet" } ``` ### Technical Analysis The loader explicitly gives `config.json` priority over environment variables. Because the project ships with both relevant values populated, normal attempts to configure `X402_MAX_PAYMENT_USD` or `X402_NETWORK` through the environment have no effect. This conflicts with the security guidance that presents `X402_MAX_PAYMENT_USD` as a default cap for unattended runs. An operator may reasonably set a lower environment cap or select testnet, while the process continues using the bundled `$10.00` limit and mainnet. The use of truthiness-based `or` also prevents a file value of zero from being represented as an intentional payment prohibition. Configuration values are not validated for type, range, finite numeric values, or permitted network names. ### Attack Path 1. An operator deploys the Skill with the bundled `config.json`. 2. The operator sets `X402_MAX_PAYMENT_USD` to a lower value or sets `X402_NETWORK=testnet`, believing the documented environment controls will take effect. ...[truncated 974 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Security-Critical Wallet Dependencies Are Not Reproducibly Pinned

Content
View full analysis
=1.0.0 httpx>=0.25.0 eth-account>=0.10.0 ``` The installation instructions at `SKILL.md:28-45` also direct users to install unpinned packages: ```bash pip install simmer-sdk ``` ```bash pip install x402[httpx,evm] ``` ### Technical Analysis The dependency declarations use only lower bounds and provide no upper bounds, lockfile, or package hashes. Every fresh installation can therefore resolve to a different version of the x402 payment implementation, HTTP client, Ethereum account library, and their transitive dependencies. These packages execute inside a process that reads an EVM private key and signs payment authorizations. A compromised, malicious, or unexpectedly incompatible future dependency release would consequently execute in a highly sensitive context. The instructions also request installation of `simmer-sdk`, although the reviewed Python implementation does not import it. Installing an unnecessary package expands the supply-chain attack surface beyond the minimum dependencies required for the declared functionality. No evidence was found that the currently named packages are typosquatted or malicious. The finding concerns unsafe and non-reproducible dependency management rather than a confirmed malicious package. ### Attack Path 1. An operator follows the setup instructions or installs from `requirements.txt`. 2. Package resolution selects a newer release than the version originally reviewed, including unrestricted transitive dependencies. 3. A compromised or incompatible package executes installation-time or import-time code. 4. The Skill later imports that package in the same process that reads `EVM_PRIVATE_KEY` or `WALLET_PRIVATE_KEY`. 5. Malicious dependency code can inspect process environment var ...[truncated 828 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill explicitly relies on sensitive capabilities: reading wallet private keys from environment variables and making arbitrary outbound network requests, including paid requests that authorize USDC spending. Because the manifest declares no permissions or allowed-tools scope, an agent runtime may grant broader access than users expect, increasing the chance of unintended fund use or data egress.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

Fetch free endpoint (no payment needed)

bash
python x402_cli.py fetch "https://api.kaito.ai/api/v1/tokens" --json

Fetch Kaito mindshare data ($0.02/data point via x402)

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This endpoint triggers a paid x402 flow, meaning an outbound request can cause the skill to sign and authorize on-chain USDC payment automatically. In the context of an autonomous agent skill, automatic payment to external URLs is materially more dangerous than ordinary HTTP egress because a prompt, downstream skill, or untrusted input could induce real fund expenditure.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

Fetch Kaito mindshare data ($0.02/data point via x402)

bash
python x402_cli.py fetch "https://api.kaito.ai/api/payg/mindshare?token=BTC&start_date=2026-02-13&end_date=2026-02-14" --json

Fetch Kaito sentiment data ($0.02/data point via x402)

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

Like the prior paid Kaito example, this is not just data egress but a workflow that may automatically spend wallet funds on an external provider. The danger is amplified by the skill's stated purpose of autonomous payment handling, which creates a direct path from agent-controlled network requests to financial loss if abused or misrouted.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

Fetch Kaito sentiment data ($0.02/data point via x402)

bash
python x402_cli.py fetch "https://api.kaito.ai/api/payg/sentiment?token=BTC&start_date=2026-02-13&end_date=2026-02-14" --json

Ask AlphaKek knowledge engine ($0.01 via x402)

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This example sends a POST body to an external service and may automatically pay for the request, combining content exfiltration risk with autonomous financial authorization. If an agent passes sensitive prompts, proprietary data, or user information in the body, the skill could leak that data to a third party while also charging the wallet.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

Ask AlphaKek knowledge engine ($0.01 via x402)

bash
python x402_cli.py fetch "https://api.alphakek.ai/x402/knowledge/ask" \
  --method POST --body '{"question": "What is the current sentiment on BTC?", "search_mode": "fast"}' --json

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

The exported helper makes it easy for other skills to programmatically invoke paid external fetches, which broadens the attack surface beyond direct CLI use. In a multi-skill agent environment, this convenience function can enable hidden or indirect paid requests unless access is constrained by policy.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

from skills.x402.x402_cli import x402_fetch

Returns parsed JSON response

data = await x402_fetch("https://api.kaito.ai/api/payg/mindshare?token=BTC")

text

## Security

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The configuration specifies "mainnet" while the skill description says payments should use USDC on Base, creating an ambiguous and potentially unsafe payment environment. If the payment library interprets "mainnet" as Ethereum mainnet or a different default network, the skill could send real funds on the wrong chain, fail closed-loop payment assumptions, or interact with unintended contracts/endpoints.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a skill for making x402 payments to fetch data from paid APIs and gated endpoints, with examples centered on API/content access. The code additionally exposes an rpc command and x402_rpc() function that authenticate to Quicknode and issue arbitrary JSON-RPC methods against user-specified networks, which is a broader blockchain node access capability than the manifest suggests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The fetch flow automatically retries with an x402-enabled client after receiving a 402 response, which can spend wallet funds without an execution-time confirmation step. In a skill context where URLs may be supplied by other agents or untrusted inputs, this creates a real risk of unintended or induced payments to attacker-controlled or misconfigured endpoints.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The stated purpose is to handle x402 402 Payment Required flows for accessing paid endpoints. _quicknode_auth() adds a separate sign-in flow that signs a Terms-of-Service SIWE message and exchanges it for a JWT, which is an additional authentication capability not implied by simple x402 payment handling for gated fetches.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: x402 has 1 known advisory(ies) (GHSA-qr2g-p6q7-w82m (x402 SDK Security Advisory)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest references x402[httpx,evm]>=1.0.0 without pinning, while the package has at least one known advisory; this makes it impossible to verify whether deployed environments are using a fixed or affected version. Since x402 is the core payment automation library for handling 402 responses and blockchain payments, uncertainty around its exact version materially increases risk in a high-trust, money-moving context.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency is only lower-bounded (httpx>=0.25.0) rather than pinned to a specific version or constrained range, which makes builds non-reproducible and can silently pull in vulnerable or breaking releases. In a payment-handling skill that accesses paid APIs and performs automated x402 flows, dependency drift in the HTTP client increases supply-chain and request-handling risk because it directly affects network-facing behavior.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
x402[httpx,evm]>=1.0.0
httpx>=0.25.0
eth-account>=0.10.0

Unverifiable Dependency: httpx has 2 known advisory(ies) (CVE-2021-41945 (Improper Input Validation in httpx); CVE-2021-41945 (Encode OSS httpx <=1.0.0.beta0 is affected by improper input validation in `http)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

httpx has known advisories, but because the manifest does not pin an exact version, there is no assurance the installed release is patched. For a skill that programmatically contacts potentially gated or third-party endpoints and handles payment-triggered retries, HTTP client flaws or parsing issues can have security consequences beyond ordinary application use.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

eth-account>=0.10.0 is unpinned, so installations may resolve to different versions over time, including versions with unresolved security defects or incompatible signing behavior. Because this skill handles EVM-based USDC payments on Base, any dependency ambiguity in account/signing code is more sensitive than in a non-financial skill.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
x402[httpx,evm]>=1.0.0
httpx>=0.25.0
eth-account>=0.10.0

Unverifiable Dependency: eth-account has 2 known advisory(ies) (CVE-2022-1930 (Regular expression denial of service in eth-account); CVE-2022-1930 (Regular expression denial of service in eth-account)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
86% confidence
Finding

eth-account has known advisories, and the lack of a precise version means the deployment may resolve to an affected release without visibility. In this skill's context, where cryptographic account handling underpins automated USDC payments, even a moderate library issue is more dangerous because it touches signing and transaction-related functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The Quicknode auth path signs and transmits a wallet-linked SIWE message automatically, without a user-facing notice at execution time. While this does not directly expose the private key, it can unexpectedly disclose wallet identity and authorize a session token, which is a meaningful privacy and consent issue when invoked by automation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.