Back to skill

Security audit

Accounts Payable Agent

Security checks across malware telemetry and agentic risk

Overview

This skill is openly designed for accounts payable, but it gives an agent real payment authority without enough hard limits, credential-scope guidance, or explicit per-payment human control.

Install only if you intend to let an agent participate in real payment workflows. Before connecting live accounts, verify and pin the AgenticBTC MCP package, use sandbox credentials first, restrict API keys with hard spend limits and recipient allowlists, require explicit human approval for live payments, authenticate any inter-agent payment requests, and store audit logs in a controlled finance system.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly enables autonomous execution of real payments across multiple rails, but it does not present a prominent warning that tool calls can move actual funds and cause irreversible financial loss. In an agentic context, this omission materially increases the risk of unsafe invocation, operator misunderstanding, and prompt-induced payment actions without informed user consent.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The configuration shows use of a live payment API key and operational payment tooling without any warning about secret handling, least-privilege scoping, or the consequences of credential compromise. If copied blindly, users may expose production credentials or grant an agent broad payment authority, enabling unauthorized transfers or account abuse.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.