Agent-to-Agent Payments

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it asks agents to connect to a remote payment service and promotes autonomous crypto payment workflows without clear limits or confirmation rules.

Review before installing. Use only with a limited wallet or test account, inspect the PayRam MCP tools separately, require human approval for each payment or fund movement, and set explicit spending limits and counterparty allowlists before allowing autonomous use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list is broad and includes common monetization and payment-related phrases that could match ordinary user queries, causing the skill to be invoked when the user did not explicitly ask to initiate payment tooling. In a payments skill, unintended invocation is more dangerous than in low-risk domains because it may steer agents toward financial workflows, external MCP connections, or transaction setup without sufficiently explicit user intent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal