T09 · Insecure Skill Coding Practices
- Location
SKILL.md:10- Finding
Unrestricted API Origin Receives Sensitive Identity, Messaging, Upload, and Payment Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches a P2P marketplace purpose, but it handles identity proofs, messages, uploads, and payments through an unrestricted configured API endpoint with limited safety warnings.
Review this carefully before installing. Only use a trusted HTTPS TRUCHEQ_API_URL, confirm where identity proofs, images, messages, wallet addresses, and payment data will be sent, and independently verify listing details, seller address, chain, token, amount, and refund expectations before paying.
SKILL.md:10Unrestricted API Origin Receives Sensitive Identity, Messaging, Upload, and Payment Data
The purchase flow instructs users to pay sellers directly via x402 while only briefly noting elsewhere that there is no escrow, but it does not prominently warn that payments are irreversible and may not provide buyer protection. In a P2P marketplace with direct seller payments, this omission can mislead users into treating the flow as safer than it is, increasing fraud and loss risk.
No suspicious patterns detected.