skills/openclaw/skills/x402-wach/Gen Agent Trust Hub

x402-wach

Pass

Audited by Gen Agent Trust Hub on Feb 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the x402-wach CLI tool to perform all primary functions, including wallet setup, authentication, and token risk analysis.
  • [EXTERNAL_DOWNLOADS]: The skill depends on the @quillai-network/x402-wach NPM package and makes network requests to https://x402.wach.ai for data retrieval.
  • [DATA_EXFILTRATION]: The skill handles and transmits sensitive user data, including email addresses and One-Time Passwords (OTPs), to the vendor's API during the login and verification processes.
  • [PROMPT_INJECTION]: The documentation includes explicit 'Hard Rules' and 'Absolute Prohibitions' intended to override agent behavior to ensure safety and payment compliance.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via external risk reports fetched at runtime.
  • Ingestion points: The verify-risk command processes data from the https://x402.wach.ai/verify-token endpoint.
  • Boundary markers: No explicit delimiters or instructions to ignore instructions within the reports are defined in the skill instructions.
  • Capability inventory: The skill has command execution and network access capabilities.
  • Sanitization: No sanitization or filtering of the external report content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 23, 2026, 12:29 PM