Install source points to URL shortener or raw IP.
Warn
- Code
- suspicious.install_untrusted_source
- Location
- mcp-server.example.json:6
Security audit
Security checks across malware telemetry and agentic risk
This payment skill is coherent, but it gives an agent paid-call and settlement authority without clear approval or spend controls.
Review before installing. Pin and verify the `settld-mcp` npm package, use a least-privilege Settld API key, and configure policy so every paid call or settlement action shows the quote and requires explicit user approval before money is spent or records are changed.
66/66 vendors flagged this skill as clean.
Detected: suspicious.install_untrusted_source