Payumoney

Security checks across malware telemetry and agentic risk

Overview

This PayUmoney skill appears legitimate, but it gives an agent broad authenticated access to payment operations without clear approval safeguards.

Review before installing. Use a least-privileged or test PayUmoney/Membrane account first, prefer pre-built read actions, and require explicit approval before refunds, payouts, settlement changes, DELETE requests, or any operation that can modify payment or business records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill exposes a generic proxy-request mechanism for a payment platform without any explicit safeguards about handling sensitive financial or personal data. In a payments context, this can lead an agent to transmit refund details, customer records, or settlement data over arbitrary endpoints or with unsafe parameters, increasing the risk of data leakage or misuse.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal