hexanon-x402-apis

Warn

Audited by Snyk on Aug 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The required runtime workflow only calls first-party, vendor-authored Hexanon HTTP APIs (e.g., Vindex sample routes, Demandex digests, OrcaTrace feeds) for structured outputs and does not describe ingesting arbitrary outsider-authored free text without first selecting specific items.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly describes pay-per-call APIs charged in USDC on Base and details the payment flow: an HTTP 402 challenge with a pay-to address, using an x402 client library (e.g., @x402/fetch, evm/viem) to pay, and provisioning a wallet key to the agent to sign/pay. Those are explicit crypto payment/wallet instructions enabling the agent to execute on-chain/payments — direct financial execution capability.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 4, 2026, 03:35 AM
Issues
2
Security Audit — snyk — hexanon-x402-apis