Security audit
MnemoPay
Security checks for vulnerabilities and agentic risk
Overview
This skill clearly describes a payment and governance integration with high-impact capabilities, but the risky functions are disclosed and accompanied by explicit safety limits.
Install only if you intend to give an agent governed access to payment, identity, memory, or durable job capabilities. Start with the default essentials tool group, keep admin/operator/all groups disabled unless you are an authorized operator, and require explicit approvals for payments or other high-impact actions.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
