x402
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a payment protocol that ingests data from external servers, which constitutes a potential injection surface.
- Ingestion points: The agent processes data from HTTP headers (
PAYMENT-REQUIRED,PAYMENT-SIGNATURE,PAYMENT-RESPONSE) and structured metadata in Model Context Protocol (MCP) and Agent-to-Agent (A2A) communications. - Boundary markers: The protocol utilizes Base64-encoded JSON to delimit payment data within headers and metadata fields, providing structural separation from natural language instructions.
- Capability inventory: The skill enables the agent to access environment-stored blockchain signing keys, sign transactions (EIP-712, Ed25519, BCS, XDR), and perform network operations to facilitate or settle payments.
- Sanitization: The documentation details rigorous validation requirements for implementations, including cryptographic signature verification, transaction simulation, balance checks, and strict adherence to time-bound authorization parameters (
validAfter,deadline).
Audit Metadata