Skills x402 Payments skill
๐Ÿ“ฆ

x402 Payments skill

Content revision r1 Medium Risk

Build x402 Payment Flows

HTTP 402 payment flows are hard to inspect and assemble safely. This skill helps Claude, Codex, and Claude Code plan custody-free x402 payments and monetize APIs.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 67 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "x402 Payments skill" from https://skillstore.io/skills/internet-court-x402.md and its manifest at https://skillstore.io/api/skills/internet-court-x402/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "x402 Payments skill". A 402 challenge for 0.01 USDC on Base.

Expected outcome:

The skill explains the requested price, payee, token, network, expiry, and next signing step.

Using "x402 Payments skill". A request to monetize an API endpoint.

Expected outcome:

The skill describes payment requirements the server can return with HTTP 402.

Using "x402 Payments skill". A signed payment authorization from a wallet.

Expected outcome:

The skill helps assemble the X-PAYMENT header for the paid retry.

Security Audit

Medium Risk
v2 โ€ข 7/20/2026 Open versioned report

All 19 static findings are false positives caused by Markdown backticks, not shell execution. The skill documents user-authorized USDC payment flows, so users should inspect payment terms before signing.

1
Files scanned
55
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Financial Transaction Capability
The documented flow can create signed payment authorizations and complete paid endpoint requests. A user could spend USDC after approving a wallet signature.
The client flow explicitly directs a payer to sign typed data, construct an X-PAYMENT header, and retry a paid request. This is an intended financial capability, not evidence of credential theft or hidden transfers.
Audited by: claude View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/internet-court-x402/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/internet-court-x402/security.svg)](https://skillstore.io/skills/internet-court-x402?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/internet-court-x402?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/internet-court-x402/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/internet-court-x402.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

internet-court. (2026). x402 Payments skill security audit report (audit version 2) [Author version unspecified]. Skillstore. https://skillstore.io/skills/internet-court-x402/audits/2

BibTeX citation

@techreport{internet-court-internet-court-x402-2026, author = {internet-court}, title = {x402 Payments skill security audit report (audit version 2)}, institution = {Skillstore}, year = {2026}, number = {2}, url = {https://skillstore.io/skills/internet-court-x402/audits/2}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "x402 Payments skill security audit report (audit version 2)" version: "unspecified" type: report authors: - name: "internet-court" date-released: "2026-07-20" url: "https://skillstore.io/skills/internet-court-x402/audits/2" identifiers: - type: other value: "skillstore:internet-court-x402:audit:2" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
65
Spec Compliance

What You Can Build

Pay a Protected API

Decode a 402 response, prepare signing data, and assemble the payment header for a paid retry.

Monetize an Endpoint

Create payment requirements that describe price, token, recipient, network, and accepted settlement terms.

Review Agent Payments

Inspect payment details before a human or wallet signs any authorization.

Try These Prompts

Decode a Payment Challenge
Use x402 to explain this 402 response in plain terms: [paste response]. Include amount, token, recipient, expiry, and network.
Prepare a Payment Header
Build the unsigned x402 payment data for this requirement: [paste requirement]. Use payer [wallet address] and show what must be signed.
Create API Payment Requirements
Create x402 payment requirements for an endpoint that charges [amount] USDC on Base to [recipient address].
Design a Paid Request Flow
Plan an end-to-end x402 flow for [service]. Include challenge review, signing, header creation, facilitator verification, and settlement checks.

Best Practices

  • Decode and review every challenge before asking a wallet to sign.
  • Confirm payee, amount, token, network, and expiry outside the payment header.
  • Use Base Sepolia for testing before sending real USDC on Base.

Avoid

  • Asking the skill to sign transactions or manage private keys.
  • Paying a 402 challenge without checking recipient and amount.
  • Assuming every facilitator supports every network, asset, or endpoint.

Frequently Asked Questions

What is x402?
x402 uses HTTP 402 responses to request payment before a protected resource is served.
Does this skill hold private keys?
No. It prepares payment data and headers, but signing must happen in an external wallet.
Which networks does it focus on?
It focuses on USDC on Base and Base Sepolia, with support for full custom payment requirements.
Can it help monetize my API?
Yes. It can generate PaymentRequirements for an endpoint that returns HTTP 402.
Does it make payments automatically?
No. A user or wallet must approve and sign the authorization before payment can proceed.
What should I verify before signing?
Verify the recipient, amount, token, network, expiry, and facilitator before signing any authorization.

Developer Details

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

3f6e026a3363e0954ede7bef0cfe88d4475de137

Maintenance freshness

7/20/2026

Usage

1 downloads ยท 0 views

File structure

๐Ÿ“„ SKILL.md

More from internet-court

View all
View all