Back to skill

Security audit

Payrexx

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Payrexx connector that can read Payrexx data and create payment gateways, with user confirmation required for write actions.

Install this only if you intend to let your agent use your connected Payrexx account. Review any proposed payload before approving gateway creation or other state-changing actions, and ensure your OOMOL Payrexx connection has only the scopes you actually need.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation text is extremely broad: it directs the agent to use this skill for ANY Payrexx-related request, including reading, creating, and updating data. That can cause over-selection of this skill whenever Payrexx is merely mentioned, increasing the chance of unnecessary access to financial data or accidental execution of write-capable actions in contexts where a narrower, task-specific tool choice would be safer.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.