Back to skill

Security audit

nano-pay

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed Nano micropayment helper, but users should treat its payment and swap commands as real financial actions.

Install only if you are comfortable with a local self-custodied wallet and real Nano payments. Keep only small working funds in the wallet, run quote/status commands before paying, protect `~/.nano-pay/wallet.json`, and treat `pay`, `send`, and `topup --execute` as commands that can move or commit funds.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documents `nano-pay topup 5 --execute` as a normal command but does not place an explicit warning at the point of use that execution will create a live swap order, spend user-controlled funds, and require `NANSWAP_API_KEY`. In a payment-oriented skill, insufficiently prominent warnings can lead an agent or user to trigger real financial transactions unintentionally, especially because the skill encourages automated command use.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.