agent-payment-x402

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches documentation, implementation guides, and configuration files from OKX's GitHub repositories and the NVIDIA NeMo toolkit repository. These resources are provided by well-known technology and blockchain service providers.
  • [COMMAND_EXECUTION]: Configures a Model Context Protocol (MCP) server to execute npx agentwallet-sdk@6.0.0. This command is used to launch a dedicated payment subprocess with specific environment variables for wallet management.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill processes payment negotiation data, prices, and status codes (HTTP 402) received from external service APIs and other autonomous agents.
  • Boundary markers: Instructions require that spending policies (budgets, allowlists) be set by the orchestrator before delegating tasks to the agent, creating a policy boundary that the agent cannot modify.
  • Capability inventory: Includes subprocess execution (via MCP), network communication for signing transactions, and access to financial credentials stored in environment variables.
  • Sanitization: The provided implementation examples use Number.isFinite for cost validation, JSON.parse with comprehensive try-catch blocks for response parsing, and explicit error paths for malformed or unexpected data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — agent-payment-x402