Payment Rails

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Payment Rails/Trolley integration, but it needs Review because it can run broad live payout-platform actions without clear safety guardrails.

Install only if you trust the publisher and intend to let an agent access Payment Rails/Trolley through Membrane. Use test or least-privilege credentials where possible, prefer discovered read-only actions first, and require explicit confirmation before any create, update, delete, batch, recipient, payment, or payout-triggering operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough that an agent could invoke it for loosely related requests involving payments, records, or workflows without confirming that the user actually intends to operate on a live payout platform. In a financial integration, over-broad routing increases the chance of unintended access to sensitive payment data or execution of payout-affecting actions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explains how to run actions and proxy API requests against a live payout platform but does not warn that these operations may read or modify sensitive financial records, recipient data, or payment state. In a payments context, lack of a clear caution materially raises the risk of accidental high-impact actions being performed without informed user confirmation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal