BoltzPay

Security checks across malware telemetry and agentic risk

Overview

BoltzPay is a disclosed payment skill for paid API access, but it should be treated as software that can spend real money.

Install only if you intend to let an agent pay for API data. Keep keys in a secrets manager, use testnet or limited-scope funds where possible, set `BOLTZPAY_DAILY_BUDGET` and per-transaction limits, review quotes before paid fetches, and require explicit user approval before any command that can spend funds.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill makes it easy to run a command that performs real paid transactions against third-party endpoints, but the documentation does not present a prominent, explicit warning at the point of use. In an agent context, unclear disclosure of financial side effects increases the risk of unintended spending, especially because the skill also emphasizes automatic payment, endpoint discovery, and streaming sessions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal