hexanon-x402-apis
Warn
Audited by Snyk on Aug 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The required runtime workflow only calls first-party, vendor-authored Hexanon HTTP APIs (e.g., Vindex sample routes, Demandex digests, OrcaTrace feeds) for structured outputs and does not describe ingesting arbitrary outsider-authored free text without first selecting specific items.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly describes pay-per-call APIs charged in USDC on Base and details the payment flow: an HTTP 402 challenge with a pay-to address, using an x402 client library (e.g., @x402/fetch, evm/viem) to pay, and provisioning a wallet key to the agent to sign/pay. Those are explicit crypto payment/wallet instructions enabling the agent to execute on-chain/payments — direct financial execution capability.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata