This payment-card skill is purpose-aligned, but it gives agents real spending power and exposes full card credentials with inconsistent documentation and incomplete guardrails.
Install only if you intentionally want an agent to spend real funds and manage virtual cards. Use a dedicated Stellar wallet with limited USDC, avoid storing high-value private keys in plaintext configs, require your MCP client to ask for approval before create_card, fund_card, get_card_details, freeze_card, or unfreeze_card, and do not allow PAN/CVV outputs to be logged, remembered, or sent through Telegram unless you accept that exposure.