Back to skill

Security audit

x402-development

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent x402 payment-development skill, but its examples can enable automatic crypto spending and unsafe credential forwarding without enough scoping.

Install only if you intend to build x402 payment flows and can manage wallet keys carefully. Use dedicated low-balance or test wallets, add explicit spending caps and allowlists before enabling auto-payment, do not reuse broad API_KEY credentials in 402 retry hooks, require HTTPS and trusted origins, and pin dependency versions in real projects.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
references/lifecycle-hooks.md:130
Finding

Bearer Token Can Be Forwarded to an Untrusted HTTP 402 Responder

Content
View full analysis
{ const apiKey = process.env.API_KEY; if (apiKey) { return { headers: { "Authorization": `Bearer ${apiKey}` } }; } }); ``` ### Technical Analysis The example reads a bearer credential from the `API_KEY` environment variable and adds it to a retry whenever the client receives an HTTP 402 response. It does not demonstrate validation of the request destination, HTTPS scheme, expected credential audience, redirect chain, or an allowlisted origin before releasing the credential. An HTTP 402 response is controlled by the destination server. Consequently, any endpoint that the application or Agent is induced to request may trigger this hook. If the x402 client accepts arbitrary or externally supplied URLs, an attacker-controlled server can return a syntactically valid 402 response and cause the subsequent request to contain the bearer token. The `paymentRequired` value is also not used to ensure that credential fallback is appropriate for the destination. This behavior exceeds minimum privilege because a process-wide environment credential may be exposed to any responding origin rather than only to the service for which it was issued. ### Attack Path 1. The application or Agent is induced to request an attacker-controlled URL, or a trusted URL redirects to an attacker-controlled origin. 2. The attacker returns an HTTP 402 response that activates `onPaymentRequired`. 3. The hook reads `API_KEY` from the process environment. 4. The client retries the request with `Authorization: Bearer `. 5. The attacker records the authorization header. 6. The attacker reuses the token against services that accept it, subject to the token's p ...[truncated 544 chars]
Remediation
View remediation
{ const requestUrl = new URL(context.request.url); if (requestUrl.protocol !== "https:" || requestUrl.origin !== trustedOrigin) { return; } const apiKey = process.env.EXAMPLE_API_KEY; if (!apiKey) { return; } return { headers: { Authorization: `Bearer ${apiKey}`, }, }; }); ``` The surrounding HTTP client should additionally reject cross-origin redirects or strip the authorization header before following them. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:102
Finding

Unpinned Package Installation Commands Create Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (22)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly targets autonomous agent payment flows and repeatedly describes accountless, programmatic micropayments, but it does not prominently warn that using the provided client patterns can spend real funds when a signing key is configured. In an agent setting, that omission is dangerous because a caller may invoke tools or wrapped HTTP clients expecting ordinary API retries, while the library may instead sign blockchain-backed payment authorizations and trigger irreversible financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The buyer example states that payment is handled automatically on a 402 response immediately after loading a private key from EVM_PRIVATE_KEY, but it does not warn that this can sign payment payloads and spend assets from the configured wallet. In practice, an agent or developer may copy this snippet into an automation context and unintentionally enable silent payment execution against any x402-protected endpoint the wrapped client reaches.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/core-concepts.md (reported line 350)May include surrounding context.

typescript
const facilitator = new HTTPFacilitatorClient({
  url: "https://api.cdp.coinbase.com/platform/v2/x402"
});

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation describes a flow where a client signs an ERC-20 approve transaction and a facilitator later broadcasts it, but it does not explicitly warn that approve grants token spending authority to Permit2 and may expose the user's funds up to the approved amount. In a payments SDK, omission of that warning is security-relevant because integrators may implement the flow without informed consent UX, increasing the chance of users unintentionally granting broad allowances.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This section explicitly says the facilitator broadcasts a signed approve transaction before settlement, yet it lacks a user-facing warning that this action can create a standing authorization for Permit2 to transfer tokens. In the context of micropayments and gas sponsorship, users may perceive the signature as payment-specific, when in reality approve can outlive the transaction and be reused if not tightly constrained.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/protocol-spec.md (reported line 33)May include surrounding context.

md
"x402Version": 2,
  "error": "PAYMENT-SIGNATURE header is required",
  "resource": {
    "url": "https://api.example.com/premium-data",
    "description": "Access to premium market data",
    "mimeType": "application/json"
  },

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/protocol-spec.md (reported line 96)May include surrounding context.

md
"x402Version": 2,
  "error": "PAYMENT-SIGNATURE header is required",
  "resource": {
    "url": "https://api.example.com/premium-data",
    "description": "Access to premium market data",
    "mimeType": "application/json"
  },

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file includes sample code that reads EVM_PRIVATE_KEY directly from the environment, which is a sensitive credential operation. The surrounding documentation does not provide any warning or guidance about secure handling of private keys, test-only use, or avoiding exposure of production secrets.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · references/python-sdk.md (reported line 156)May include surrounding context.

register_exact_evm_client_sync(client, EthAccountSigner(account))

session = x402_requests(client) response = session.get("http://localhost:4021/weather")

text

## Client: Solana Support

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The example constructs a signer from SVM_PRIVATE_KEY, which involves direct use of a sensitive wallet secret. The markdown does not warn readers about secure storage, least-privilege/test-key usage, or the risk of exposing wallet material when following the example.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The reference explicitly states that the Stellar Testnet RPC uses an HTTP endpoint, which permits man-in-the-middle tampering and observation of RPC traffic. Even on testnet, developers often reuse configurations, wallets, and operational patterns in ways that can lead to unsafe production deployments or acceptance of falsified simulation/transaction data during testing.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/svm-scheme.md (reported line 133)May include surrounding context.

md
- **Cache key**: the transaction **message hash** (as of TS v2.14.0 / Python 2.12.0 / Go 2.13.0). Earlier versions keyed on the full Base64 signed-transaction string, which let an attacker bypass the cache by randomizing the mutable fee-payer signature slot - keying on the message hash closes that bypass.
- **TTL**: 120 seconds (covers Solana blockhash lifetime of ~60-90s plus margin)
- **Behavior**: If key exists in cache, reject with `duplicate_settlement` error; otherwise insert and proceed
- **Eviction**: Entries older than 120 seconds are automatically removed
- **Thread safety**: Go uses `sync.Mutex`; Python uses `threading.Lock`; TypeScript relies on single-threaded event loop

### SDK Implementation

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file includes example code that reads process.env.EVM_PRIVATE_KEY and process.env.SVM_PRIVATE_KEY, which are sensitive credentials. While this is normal for SDK usage, the surrounding documentation does not include an explicit warning or caution about securely storing, scoping, and protecting these secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The fetch example uses plain HTTP for a payment flow that carries signed payment material, enabling interception, replay support information leakage, or manipulation by an on-path attacker. In a payments SDK, insecure transport in examples is especially risky because users often copy documentation verbatim into real integrations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The facilitator setup example initializes a signing scheme with process.env.FACILITATOR_KEY, which is a highly sensitive secret controlling settlement behavior. The documentation does not provide any warning about secure secret handling, rotation, or avoiding exposure through logs and repository files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation states that the client auto-creates XRPL tickets when none are available, but does not prominently warn that this submits a separate on-chain transaction and locks owner reserve. In a payments SDK context, hidden state mutation and balance consumption can cause unexpected spend, reserve exhaustion, failed follow-on transactions, and operational surprises for integrators.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file includes sample code that loads process.env.XRPL_SEED, which is a sensitive wallet secret. The surrounding documentation does not warn users that this value is highly sensitive and must be protected, so the skill description omits a relevant safety warning about credential handling.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 27)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 31)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 54)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 147)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file includes example code that reads process.env.APTOS_PRIVATE_KEY, which involves sensitive credential access. The surrounding documentation does not warn users to protect the key, avoid exposing it in logs or source control, or use secure secret management.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/lifecycle-hooks.md:74