Critical-risk tools in Wisely x402 Agent-Payment Infrastructure
11 of the 65 tools in Wisely x402 Agent-Payment Infrastructure are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
gift_card_wallet_bridge_setupFinancialAlias for setup_local_wallet_bridge. Use for crypto-to-gift-card flows where the user signs locally and wants receipts or gift-card records saved locally.
-
wallet_bridge_setupFinancialAlias for setup_local_wallet_bridge. Use when the user wants their wallet to stay local while the agent uses Wisely x402 payment sessions.
-
wisely_creator_catalog_recommendFinancialRecommend the next creator-catalog action for a subscriber situation, including fetch instructions or paid endpoint 402 probe instructions.
-
x402_doordash_gift_card_processFinancialReturn or run the full DoorDash gift-card-funded quote flow: cart totals, Bitrefill custom range, $15 minimum, crypto conversion/gas, $0.75 service fee, 1% fee, approval packet,...
-
x402_gift_card_merchant_quoteFinancialQuote any Bitrefill-supported merchant gift-card purchase after product details are fetched, using $0.75 + 1% plus explicit route/network costs.
-
x402_invoke_serviceFinancialInvoke a paid service through /ai/invoke with x402 proof or developer credit.
-
x402_purchase_creditsFinancialCreate or top up reusable developer credits through x402.
-
x402_quote_conversionFinancialQuote a live executable conversion from the caller's crypto into required Base USDC x402 settlement.
-
x402_quote_serviceFinancialQuote a Wisely-hosted AI/data service and payment route.
-
x402_rye_commerce_handoffFinancialReturn the Rye x402 checkout-intent flow for commerce URL checkout attempts, including DoorDash-via-Rye caveats, quote examples, and final-confirmation approval rules.
-
x402_wallet_handoffFinancialCreate a short-lived hosted wallet signing session for ChatGPT/MCP clients. The user opens a signing URL, chooses an injected wallet, mobile wallet app, or configured WalletConn...
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.