Back to plugin

Security audit

pay.sh Bridge

Security checks for vulnerabilities and agentic risk

Overview

No artifact-backed suspicious behavior was identified, but the workspace artifacts could not be read in this run.

Treat this as an incomplete review: the local sandbox prevented reading metadata.json and artifact files, so install only after a successful artifact inspection confirms the skill's purpose, permissions, install steps, and data handling.

Static analysis

No suspicious patterns detected.