Snaplii A2M Payment
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's stated purpose (agent-to-merchant payments via Snaplii gift cards) aligns with its instructions and files; there are no obvious mismatches, but you should vet the external pip package and the Snaplii service before use.
This skill appears coherent for making agent-driven purchases with Snaplii gift cards, but you should: 1) review the snaplii-cli PyPI package and its GitHub source before installing (look for how it stores/handles API keys and redemption codes), 2) confirm the MCP server process (snaplii-mcp) will not persist secrets or exfiltrate data, 3) verify the Snaplii app's API key scope and spending limits in the mobile app, and 4) ensure you (the user) always explicitly confirm purchases when the agent asks. Because the registry bundle is instruction-only, the real security surface is the external snaplii-cli package and Snaplii service — vet those before use.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
Risk analysis
No visible risk-analysis findings were reported for this release.
