Back to skill

Security audit

IoMarkets Topup

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed purchase workflow for eSIMs and mobile top-ups, with explicit human confirmation and budget controls before spending funds.

Before installing, understand that this skill can help spend USDC on real eSIMs or phone top-ups. Use hosted mode if you want to keep wallet signing outside the MCP server; if using local mode, keep the mnemonic file protected and set conservative per-session and per-order budgets. Always verify the phone number, operator, delivered item, and USDC price before approving a purchase.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill description is broad enough to activate on generic travel, mobile data, recharge, or FX-related requests, which can cause an agent to enter a purchase-oriented workflow when the user may only be seeking information. Because this skill can lead to real-money transactions, overbroad triggering increases the chance of unnecessary quoting, collection of phone numbers, or progressing toward a purchase without sufficiently clear user intent.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.