PayLobster

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The 'paylobster' skill bundle provides an extensive financial infrastructure for AI agents on the Base network, including tools for escrows, token swaps, and a 'CoinFlip' gambling contract. It is classified as suspicious because it requires high-privilege access (PAYLOBSTER_PRIVATE_KEY) and promotes the use of a hosted, opaque MCP server (paylobster.com/mcp/mcp), which introduces significant remote execution risks. Furthermore, the 'natural language payments' feature (natural_pay tool) creates a high-risk surface where prompt injection could potentially trigger unauthorized financial transactions.