Back to skill

Security audit

Pop Pay Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about enabling local card-based checkout automation, but its default workflow can let an agent inject payment details and submit purchases without per-transaction human approval.

Review this carefully before installing. Use a pinned, verified package version, install in a contained environment, set POP_AUTO_INJECT=false and POP_REQUIRE_HUMAN_APPROVAL=true, keep low spend limits, and only allow explicit merchants or domains you trust.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:54
Finding

Unpinned Third-Party Payment Package Installation

Content
View full analysis
Remediation
View remediation
``` 3. Distribute or link to the exact source revision corresponding to the package release so that the payment implementation can be independently audited. 4. Use reproducible builds and sign release artifacts or attestations. 5. Recommend installation in a dedicated virtual environment with only the permissions required for browser injection and keychain access. 6. Verify publisher identity and package provenance before installation. 7. Add an upgrade procedure requiring review and integrity verification before changing the pinned version. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:67
Finding

Payment Automation Defaults Do Not Require Human Approval

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

bash
# Install from PyPI (https://pypi.org/project/pop-pay/)
pip install pop-pay
pop-pay setup          # securely stores your card in the system keychain
pop-pay setup --profile   # stores billing info (name, address, email)

Static analysis

No suspicious patterns detected.