razorpay monitor

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a disclosed Razorpay payment-monitoring helper with read-only API use, but users should treat WhatsApp or Telegram alerts as sensitive financial notifications.

Install only if you are comfortable sending payment-monitoring alerts through WhatsApp or Telegram. Configure recipients carefully, keep Razorpay keys in environment variables, and prefer minimal, masked alert content for customer and payment details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly sends payment summaries, failed-payment details, settlements, and dispute alerts over WhatsApp or Telegram, but it does not clearly warn users that these third-party messaging channels may expose sensitive business or customer-related data outside Razorpay. Even with masking guidance later in the document, operational and financial metadata can still be sensitive and may be retained, forwarded, or accessed by unintended parties on those platforms.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal