The skill mostly does what it advertises, but it also includes under-disclosed crypto payment execution paths and unsafe credential/public-server guidance that users should review carefully.
Install only if you are comfortable running a local payment server that becomes publicly reachable. Put API keys in a local .env or secret store, not in chat; verify the real payment recipient in PingPay/HOT PAY; remove or separately review the invoice-paying NEAR Intents code before use; and do not rely on the advertised webhook signature protection unless you add actual verification.