Back to skill

Security audit

CAI: pay-openrouter-fee

Security checks across malware telemetry and agentic risk

Overview

The skill appears intended to pay OpenRouter bills, but it can move real wallet funds and does not clearly frame the transfer risk or recipient-verification requirements.

Install only if you are comfortable letting the agent prepare real wallet payments. Before any transfer, independently verify the OpenRouter billing recipient, token, chain, amount, and account crediting path, and assume crypto-style transfers may not be recoverable if sent incorrectly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill facilitates sending funds from a custodial wallet based on agent-discovered payment details, but it does not clearly warn users that this may move real assets and that crypto-style transfers can be irreversible. In this context, the omission is meaningful because the workflow explicitly includes resolving a recipient and executing a transfer after only a confirmation step, which increases the chance of user misunderstanding, social engineering, or mistaken payment to a wrong address.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.