agent-payment-x402
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches documentation, implementation guides, and configuration files from OKX's GitHub repositories and the NVIDIA NeMo toolkit repository. These resources are provided by well-known technology and blockchain service providers.
- [COMMAND_EXECUTION]: Configures a Model Context Protocol (MCP) server to execute
npx agentwallet-sdk@6.0.0. This command is used to launch a dedicated payment subprocess with specific environment variables for wallet management. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill processes payment negotiation data, prices, and status codes (HTTP 402) received from external service APIs and other autonomous agents.
- Boundary markers: Instructions require that spending policies (budgets, allowlists) be set by the orchestrator before delegating tasks to the agent, creating a policy boundary that the agent cannot modify.
- Capability inventory: Includes subprocess execution (via MCP), network communication for signing transactions, and access to financial credentials stored in environment variables.
- Sanitization: The provided implementation examples use
Number.isFinitefor cost validation,JSON.parsewith comprehensive try-catch blocks for response parsing, and explicit error paths for malformed or unexpected data.
Audit Metadata