Agnic Pay for Service

Security checks across malware telemetry and agentic risk

Overview

This skill is purpose-aligned for paid x402 API calls, but it can spend USDC and send request data to arbitrary third-party endpoints without requiring a final price/data confirmation or spending cap.

Install only if you intentionally want an agent to make paid x402 API calls. Before each payment, require the agent to show the endpoint, HTTP method, request body/headers, exact price, and a conservative `--max-amount`; use a limited wallet or token containing only funds you are willing to spend.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This skill enables real-money network actions by spending USDC and sending request data to third-party endpoints, but it does not prominently require an explicit user-facing warning or confirmation immediately before payment execution. In an agent context, that omission increases the risk of unintended spending, privacy leakage, or ambiguous user consent, especially because the skill is user-invocable and designed to call arbitrary paid URLs.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal