Snaplii A2M Payment

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's stated purpose (agent-to-merchant payments via Snaplii gift cards) aligns with its instructions and files; there are no obvious mismatches, but you should vet the external pip package and the Snaplii service before use.

This skill appears coherent for making agent-driven purchases with Snaplii gift cards, but you should: 1) review the snaplii-cli PyPI package and its GitHub source before installing (look for how it stores/handles API keys and redemption codes), 2) confirm the MCP server process (snaplii-mcp) will not persist secrets or exfiltrate data, 3) verify the Snaplii app's API key scope and spending limits in the mobile app, and 4) ensure you (the user) always explicitly confirm purchases when the agent asks. Because the registry bundle is instruction-only, the real security surface is the external snaplii-cli package and Snaplii service — vet those before use.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.