Paegents

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's requests and instructions are coherent with a payment/escrow integration: it asks only for the API URL, API key, and agent id needed to call the Paegents public API and its SKILL.md stays at the public integration surface.

This skill appears to be a legitimate integration guide for the Paegents payment/escrow platform and only needs the API URL, API key, and agent id. Before installing: verify you trust the Paegents API endpoint and that the PAEGENTS_API_KEY you provide is scoped appropriately (least privilege) and stored securely; do not paste private wallet keys or secret service keys into chat — keep signing/local keys in your keystore/HSM; confirm the skill's upstream source (SKILL.md references a homepage and GitHub repo while registry metadata shows source unknown/homepage none); and be aware the skill can act with whatever API key you provide, so only install it if you trust that key/endpoint. Because the skill is instruction-only and does not install code, install-time risk is low, but operational risk depends on the privileges of the provided API key.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.