Back to skill
Skillv1.0.3

VirusTotal security

Coupa Pay · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 22, 2026, 2:16 PM
Hash
a8b46623627d8aec432403caf2030cbc699180e529330fd6f19467e3ee19445d
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: coupa-pay Version: 1.0.3 The skill facilitates Coupa Pay integration by instructing the AI agent to perform high-risk operations, including global software installation (npm install -g @membranehq/cli) and shell command execution for authentication and data management. While the instructions in SKILL.md align with the stated purpose and include security-conscious advice regarding credential management, the requirement for broad shell and network access to interact with the Membrane CLI constitutes a significant attack surface.
External report
View on VirusTotal