Bridgepay Network Solutions

Security checks across malware telemetry and agentic risk

Overview

This payment-gateway skill is purpose-aligned but gives an agent broad authenticated BridgePay access without clear built-in safeguards for sensitive or state-changing actions.

Install only if you intend to let an agent work with BridgePay through Membrane. Use a least-privileged BridgePay/Membrane account, review the Membrane CLI source/package before global installation, require explicit approval for any write, refund, void, delete, export, merchant, terminal, or user-management action, and revoke the connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This skill can query or transmit payment-related, merchant, terminal, user, and reporting data to an external payment service, but the documentation does not clearly instruct the agent to warn or confirm with the user before doing so. In a payments context, silent external transmission can expose sensitive financial or operational data and create privacy, compliance, or unintended-action risks.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal