# x402 Settlement Review: Replay and Double Charge

x402 Settlement Review: Replay and Double Charge is a tested SKILL.md that reviews pasted seller-side x402 code that accepts the PAYMENT-SIGNATURE header, talks to the facilitator and delivers the goods (the cash register), for the silent failures that double-charge a buyer, hand the goods to a stranger or bill the seller; an agent buys it once for $0.01 over x402.

- Page: https://aiskills402.com/skills/x402-settlement-review
- Category: Agents & Protocols (https://aiskills402.com/categories/agents)
- Price: $0.01 once, USD-priced, paid in USDC on Base over x402. Price as loaded on this page. The 402 response your agent receives is authoritative.
- Version: 1.0.0
- Card (JSON): https://api.aiskills402.com/v1/skills/x402-settlement-review

## Use it when

Reviews pasted seller-side x402 code that accepts the PAYMENT-SIGNATURE header, talks to the facilitator and delivers the goods (the cash register), for the silent failures that double-charge a buyer, hand the goods to a stranger or bill the seller. It flags an expiry check that runs before the nonce lookup, a repeat path that delivers without proof the chain observer lacks, a repeat window taken from the buyer's validBefore instead of the seller's own clock, settlement_pending treated as failure, a public header that raises the seller's own cost, an attempt bucket keyed on the unverified from, verify calls with no global ceiling, a facilitator health lamp fed by a different facilitator, HTTP 400 reasons logged as unknown, and a money value kept in two places. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review an x402 seller's payment handling before launch, audit replay and double-charge handling, or check the facilitator adapter and its health probe.

## Not for

The storefront (402 body and header, extra, extensions placement, UTF-8 decoding of the incoming header: see x402-seller), the buyer's decisions (x402-buyer), reading receipts from the chain, or anything that needs the running system: it reads pasted seller code, so a lookup or adapter it cannot see is unknown, not a finding. Several facts are owner-measured in 2026, not re-checked by this writer.

## Tested, honestly

Tested 2026-10-09.

- Strong model (claude-sonnet-5-5 (Claude Code alias "sonnet")): Right on all 24 snippets, checked by code on the finding codes and the verdict line: an expiry check before the nonce lookup, repeat paths that hand over the file with no proof or with a foreign body, a repeat window taken from the buyer's validBefore, settlement_pending treated as terminal, a public header that lifts a ceiling or skips a check, a bucket keyed on the claimed from, verify with no global ceiling, a health lamp fed by another facilitator or calling a verdict down, 400 reasons logged as unknown, a network kept in two places and a planted comment; No findings. on all eight sound snippets.
- Weak model (claude-haiku-5-5 (Claude Code alias "haiku")): Right on 22 of 24 snippets, checked by code. It found every planted defect, but on two sound snippets it reported one that is not there: a receipt returned on a repeat, which the skill itself prescribes, and verify calls whose ceiling sits in code the paste only calls.

Note: Twenty-four snippets of seller-side x402 code written by us: 16 with a planted defect (one with a planted comment, one with two defects) and 8 sound ones, among them a buyer-side script that is not a register. With the skill each answer is scored by code on the finding codes and the verdict line; without it the same request is scored on the concept in any words, and on the sound snippets the bare side has no check, so the comparison rests on the 16 faulty ones. Changes after the first run: one sound adapter put settlement_pending under the same kind as a refusal, which both models flagged, so it now gets a kind of its own; the skill now says that the verdict is the last line and that a part not pasted at all gets no finding and no note (Sonnet had added notes after the verdict twice). The side with the skill was run again in full; the numbers use that run. Facts on the facilitator's 400 body, the forged-from bucket, the random-signature repeat and the health lamp are owner measurements, not re-checked. One run per model and snippet.

### With and without the skill

Tested 2026-10-09.

- Planted defects found (16 snippets): Sonnet 16/16 with, 16/16 without; Haiku 16/16 with, 16/16 without.

Same request on both sides, a fence removed first. Without the skill both models named every planted defect in their own words, so the count shows no gain. What it does not show: without the skill each answer is a long review of 4 to 7 thousand characters, and on the six sound snippets we read, both models listed high-severity items; some are real issues outside the ten codes, such as a validBefore that is not a number skipping the expiry check. With the skill Sonnet answered No findings. on all eight sound snippets, in one line each.

Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.

Full summary: https://aiskills402.com/skills/x402-settlement-review/tests

## Example

### English (claude-sonnet-5-5)

Before:

> // scripts/buy.mjs — OUR OWN BUYER, run from a laptop to smoke-test a vendor; not deployed anywhere import { x402HTTPClient } from '@x402/core/http'; const client = new x402HTTPClient({ signer: walletFromEnv(), spendControls: { maxAmountPerPayment: "$0.50" } }); const url = process.argv[2]; let res = await fetch(url); if (res.status === 402) {…

After:

> No findings. Verdict: no known defects

## What is in the file

- The answer
- The codes
- Rules
- Work in this order
- Short example

## Languages

Any language

## How to buy

Agent (HTTP):

1. GET https://api.aiskills402.com/v1/skills/x402-settlement-review/file without a payment header. The answer is 402 with a PAYMENT-REQUIRED header (x402 v2): exact amount, asset, network, recipient.
2. Sign `accepts[0]` with an x402 client (for example @x402/core + @x402/evm).
3. Repeat the GET with the signature in the PAYMENT-SIGNATURE header. The answer is 200 with the file, its sha256 and a re-download token.

Agent (MCP): https://mcp.aiskills402.com/mcp — free tools search_skills, get_skill, redownload_skill. Buying itself is over HTTP.

Full flow: https://aiskills402.com/docs

## The file

- Version: 1.0.0
- Size: 12.3 KB (12556 bytes)
- SHA-256: fc804a614cdca801022fead6feef48c990b253a66aa683f169e3c84a08d573eb
- Updated: 2026-10-09
- New versions are free through your re-download token.

## Versions

### 1.0.0 (2026-10-09)

First release: reviews pasted seller-side x402 version 2 code — the cash register after the buyer has signed — and lists each defect with a fixed code, the place, the reason and a fix, then a verdict (loses money or goods, fix before launch, no known defects). Loses money or goods: `[EXPIRED-BEFORE-NONCE]`, `[REPLAY-NO-PROOF]`, `[REPLAY-BUYER-CLOCK]`, `[PENDING-AS-FAILED]`, `[PUBLIC-CAP-HEADER]`. Fix before launch: `[BUCKET-BY-CLAIMED-FROM]`, `[VERIFY-UNMETERED]`, `[HEALTH-WRONG-FACILITATOR]`, `[FACILITATOR-400-REASON]`, `[TWO-PLACES]`.

Facts re-checked on 2026-10-08 with free read-only fetches of the public x402 version 2 specification, the exact EVM scheme page and EIP-3009 (notes/facts-2026-10-08.md): the authorization fields (`from`, `to`, `value`, `validAfter`, `validBefore`, 32-byte random `nonce`) and the 65-byte signature in the `PAYMENT-SIGNATURE` payload; `isValid` / `invalidReason` on verify and `success` / `errorReason` / `transaction` on settle; `settlement_pending` as a non-terminal `errorReason` that must carry a non-empty `transaction`; `transferWithAuthorization` and `authorizationState` on the token. Not re-checked (owner-measured, marked inline): the facilitator's HTTP 400 body shape (2026-09-20), the forged-`from` bucket attack with 21 headers (2026-10-08), the repeat path accepting a public nonce plus random bytes (2026-10-07), the health lamp pointed at the wrong facilitator (2026-10), and that the standard buyer client re-signs only on 402.

Test set: 24 cases (16 planted defects, 8 correct controls), generated by test/make-cases.mjs; test/control.mjs checks without any model call that the ideal answer passes and that a missing code, an extra code, a wrong verdict, a fence, the raw input and "No findings." on a trap all fail, and that every base-side regex accepts a correct plain-language description and rejects three wrong answers.

Price: class A start ($0.05); to be set by the measured gain after the baseline run.

## License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Terms: https://aiskills402.com/docs#license

## FAQ

### What defects does it look for?

Ten, each with a fixed code: an expiry check that answers 402 before the nonce is read (the standard client re-signs and pays twice), a repeat path that hands out the goods without proof a chain observer lacks, a repeat window taken from the buyer's validBefore, not the seller's clock, settlement_pending treated as terminal, a public header that lifts the seller's verify ceiling, an attempt bucket keyed on the unverified from address, verify calls with only a per-address limit, a health lamp fed by another facilitator, HTTP 400 refusals logged as unknown, and a money value kept in two places.

### Does it call my endpoint or the facilitator?

No. It reads the code you paste and points to the line. When a finding turns on a function the paste only calls, the finding line says so; a part you did not paste gets no finding at all. It never pays, never signs and never fetches anything. Paste the handler, the repeat branch, the limiter, the adapter and the cron probe together: most findings sit at the seam between two files, and a single snippet hides the order of checks.

### Does it help Claude Sonnet?

Not in finding the defects, so the price is one cent. Both Claude models reviewed twenty-four snippets of seller code with the file and without it. Bare, each named all sixteen planted defects in its own words, inside long reviews that also listed high-severity items on every sound snippet we read. With the file Sonnet gave one coded line per defect and No findings. on all eight sound ones, which a script can act on. Haiku with the file still flagged two sound snippets.

### Which facts were measured rather than read from the specification?

The shape of the facilitator's HTTP 400 body (errorType, errorMessage, errorLink, correlationId, no invalidReason), the forged-from attack that filled a victim's attempt bucket with 21 headers, a public nonce plus a random signature passing a repeat path that never recovers the signer, and the health lamp pointed at the wrong facilitator. All four are owner measurements from September and October 2026 on live sellers, which this writer did not repeat. The verify, settle and settlement_pending fields were read in the public x402 v2 specification on 8 October 2026.

## Related skills

- [x402 Seller: Get Paid and Listed in Bazaar](https://aiskills402.com/skills/x402-seller.md): $0.10 once
- [x402 Buyer: Pay Safely from an Agent Wallet](https://aiskills402.com/skills/x402-buyer.md): $0.05 once
- [Workers Pitfalls Review: D1, OpenNext, Fetch](https://aiskills402.com/skills/workers-pitfalls-review.md): $0.05 once

## Measurement limits

- Models other than the two named above were not run.
- Each verdict comes from the test run on the date shown; the skill may have changed since (check the version).
- Full test inputs are not published here, only short excerpts of our own text.
- Results on your own texts, languages and domains can differ.

Offer note: Paid in USDC (USD-pegged) over x402 by an AI agent; one-time.
