Back to skill

Security audit

Mayar Payment Integration

Security checks for vulnerabilities and agentic risk

Overview

This Mayar payment skill is broadly legitimate, but its setup and examples handle live payment credentials and payment events in ways that need careful review before use.

Install only if you are comfortable giving the agent access to a Mayar payment account and customer transaction data. Before production use, pin and review the MCP dependency, avoid putting live tokens directly in command arguments or committed config, verify webhooks before fulfillment, avoid shell-string examples for user-controlled fields, and add consent/redaction controls for WhatsApp and reporting workflows.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:35
Finding

Automatic Execution of an Unpinned Remote npm Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/integration-examples.md:403
Finding

Shell Command Injection Through Interpolated Invoice Fields

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/api-reference.md:409
Finding

Webhook Example Processes Payment Events Without Sender Authentication

Content
View full analysis
{ // Respond immediately res.status(200).json({ received: true }); // Process async processPayment(req.body).catch(console.error); }); ``` The subsequent guidance does not provide an implemented verification mechanism: ```markdown ### 3. Validate Webhook Signature (If Mayar provides signature verification - check docs) ``` ### Technical Analysis The webhook handler acknowledges and processes the request body without first proving that the request originated from Mayar. The example does not validate a cryptographic signature, authenticate the source, enforce replay protection, or independently confirm the reported transaction with Mayar. Webhook endpoints are normally Internet-accessible. Therefore, request body fields such as event type, transaction status, invoice identifier, customer identifier, and amount must be considered attacker-controlled until authenticated. Schema validation alone would not establish authenticity. The surrounding text recognizes signature validation as a best practice but leaves it conditional and unimplemented. Applications copying the complete handler could consequently treat a forged `transaction.paid` event as authoritative. ### Attack Path 1. An application deploys the documented webhook handler and uses `processPayment` to update orders or grant access. 2. An attacker identifies or guesses the public webhook endpoint. 3. The attacker submits a fabricated payload representing a successful payment for an unpaid invoice or attacker-controlled customer. 4. The endpoint immediately returns success and forwards the unverified body to `processPayment`. 5. The application marks the order as paid, delivers goods, issues tickets, grants membership, or creates digital access. 6. If d ...[truncated 755 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (17)

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The example explicitly discusses sending access credentials after payment and pairs that with WhatsApp delivery of account-access information. Delivering credentials or sensitive access details through chat increases the chance of account compromise through device theft, message interception on linked devices, or disclosure on shared phones, especially because messaging platforms are not ideal channels for secret distribution.

Content

Scanner excerpt · references/integration-examples.md (reported line 235)May include surrounding context.

md
// 3. Grant course access
  await grantCourseAccess(paidInvoice.customer.email);
  
  // 4. Send access credentials
  message({
    action: 'send',
    channel: 'whatsapp',

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: mayar-payment
description: Mayar.id payment integration for generating invoices, payment links, and tracking transactions via MCP. Use when needing to: (1) Create payment invoices/links for customers, (2) Track payment status and transactions, (3) Generate WhatsApp-friendly payment messages, (4) Handle Indonesian payment methods (bank transfer, e-wallet, QRIS), (5) Manage subscriptions/memberships, or (6) Automate payment workflows for e-commerce, services, or digital products.
---

# Mayar Payment Integration

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to place a live API token into a local credentials file but does not warn about secret handling, shell history exposure, file backup/sync leakage, or avoiding committing such files to source control. In a payment integration context, compromise of this token could allow unauthorized access to invoices, transactions, balances, and customer/payment workflows.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

cat > ~/.config/mayar/credentials << EOF MAYAR_API_TOKEN="your-jwt-token-here" EOF chmod 600 ~/.config/mayar/credentials

text

### 2. Configure MCP Server

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The MCP configuration example places the Authorization token directly in a persistent JSON config entry, creating a strong risk of accidental disclosure through source control, backups, support bundles, or workstation compromise. Because this is a payment platform credential, exposure could enable unauthorized API use against financial and customer data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The authentication section tells users to use Bearer tokens and obtain API keys, but it does not warn against hardcoding, exposing, or improperly storing those secrets. In practice, documentation omissions like this often lead to keys being committed to source control, embedded in client-side code, or leaked through logs, enabling unauthorized API access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

Production:

text
https://api.mayar.id/hl/v1/

Sandbox (Testing):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 25)May include surrounding context.

Production:

text
https://api.mayar.id/hl/v1/

Sandbox (Testing):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

Sandbox (Testing):

text
https://api.mayar.club/hl/v1/

Core Endpoints

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 30)May include surrounding context.

Sandbox (Testing):

text
https://api.mayar.club/hl/v1/

Core Endpoints

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The webhook payload example includes customer name, email, and mobile number, but the document does not instruct users to minimize, protect, redact, or securely store this PII. In a payment-processing context, implementers may log or forward webhook bodies by default, which increases privacy, compliance, and data-exposure risk if systems are compromised or misconfigured.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file includes example flows that transmit customer phone numbers, payment links, invoice codes, amounts, and related transactional details via WhatsApp. The surrounding documentation does not warn readers that these examples handle and send user data through external messaging channels, which matches the markdown-specific missing-warning criterion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The payment-status polling example retrieves transaction records and automatically messages customers based on payment state, and the later reminder flow does the same for unpaid invoices. The markdown presents this as routine automation but does not disclose the privacy, consent, or operational implications of monitoring payment data and initiating outbound messages.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Multiple examples hard-code Indonesian locale conventions, such as toLocaleString('id-ID'), Rupiah formatting, Indonesian-language message text, and later guidance to always use Jakarta timezone. This effectively forces a specific language/locale behavior without offering opt-in or clearly stating that the skill is limited to an Indonesia-specific deployment context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The best-practices section explicitly instructs implementers to always use Jakarta timezone, creating a hard locale requirement. Because the document does not provide a user/deployment choice or narrowly justify the regional constraint, this matches the natural-language locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation instructs users to submit personally identifiable information such as name, email, phone number, and customer transaction details to payment and portal tools, but provides no privacy, minimization, retention, or consent guidance. In an agent skill context, this omission can normalize unsafe handling of customer data and increase the risk of over-collection, accidental disclosure, or noncompliant processing when downstream tools are invoked automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The daily revenue report example aggregates transaction data and sends sales details to an admin over WhatsApp. The markdown does not warn that the report may expose sensitive financial or customer-linked business information through a third-party messaging platform.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.