Back to skill

Security audit

MagicPay

Security checks for vulnerabilities and agentic risk

Overview

MagicPay is a broad payment, Memory, and email integration, but the reviewed artifacts disclose those capabilities and consistently bind sensitive actions to user intent, OAuth, exact operation IDs, and MagicPay approval flows.

Install only if you are comfortable connecting a remote OAuth payment service that can help execute purchases, transfers, Memory reuse, email receipt handling, and subscription workflows. Use explicit wording for spending and Save requests, review MagicPay approval screens carefully, and avoid asking it to store passwords, API keys, identity documents, or other protected values unless you intentionally want them persisted in MagicPay Memory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill description is extremely broad, covering payments, memory, email, account readiness, optional choices, human input, and recovery. This can cause the orchestrator to invoke the skill for many unrelated or loosely related requests, increasing the chance that a payment-capable remote skill is activated in contexts where sensitive data handling or transactional authority is unnecessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The route 'Funding methods, link, or addresses | Use the exact funding action requested' is underspecified and does not define strict eligibility checks or disambiguation rules before invoking a funding action. In a payment skill, that ambiguity can cause the agent to select an unintended funding flow, surface the wrong funding instrument or address, or act on loosely phrased user input in ways that could misroute funds or expose sensitive payment context.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/development-session-review.md (reported line 33)May include surrounding context.

md
inspect development-only logs and read-only database projections using the
   exact identifiers and the narrowest useful time window. Prefer the installed
   Supabase integration or the repository's supported read-only diagnostic
   command. Never ask the user to paste a token, query production, scan another
   user's rows, or print secret-bearing payloads.
4. When source is available, trace from the first unexpected state through its
   caller and recovery path. Read focused tests and migrations too. A later

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/host-browser-payments.md (reported line 29)May include surrounding context.

md
`run_browser_payment` call:

1. Fetch only the direct Frankfurter pair
   `https://api.frankfurter.dev/v2/rate/{MERCHANT_CURRENCY}/USD`, replacing the
   placeholder with the observed uppercase ISO currency. Require a successful
   JSON response whose `base` is that merchant currency, whose `quote` is
   `USD`, and whose `rate` is positive. Do not use a search result, a broad rate

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/host-browser-payments.md (reported line 58)May include surrounding context.

md
returned expiry and host-required confirmations; MagicPay adds no redundant
confirmation of the same approved facts, and neither do you. After MagicPay
approval the only confirmation left is one the host itself requires for the
final action; do not ask the user to approve the same payment again in chat.
Use `browserExecution.card.billingAddress` when provided. Adapt it to the
merchant's current form; if required billing details are still missing, use
Memory or the existing input flow. Without a card address, follow the ordinary

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill extends beyond payment execution by instructing the agent to automatically retrieve and present purchased files after payment. That broadens authority from 'pay' to 'access/download content,' which can expose user data, trigger unintended downloads, or cause the agent to interact with post-purchase resources the user did not explicitly authorize in that moment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to automatically follow delivery links and retrieve purchased files without an explicit user-facing warning or opt-in for post-payment actions. Even after a legitimate payment, automatic downloads or content retrieval can affect privacy, local data handling, and user expectations, especially if the delivered artifact contains sensitive or unexpected material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guidance explicitly states that saving sensitive values such as passwords and API keys does not require an additional confirmation. In a payment and identity/memory skill, this weakens user consent protections and increases the risk of unintentionally persisting highly sensitive secrets due to ambiguity, prompt injection, or mistaken agent interpretation of user intent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/memory.md (reported line 219)May include surrounding context.

Example materialize_memory_items input for Profile plus Passport (synthetic identifiers only). In a real call every identity, revision and field key comes from the same footprint; this example grants no approval and contains no values:

json
{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/payment-operations.md (reported line 103)May include surrounding context.

md
agent then waits on the same `runId` and same operation. If the balance remains
insufficient, leave the recovery waiting for another durable top-up; do not scan
other executing requests or create a replacement. Pending approvals require an
explicit user decision even if they originally matched Auto-Approve. An unavailable
funding check offers a read refresh; it cannot authorize payment. Existing request,
approval, and seller deadlines still apply; top-up does not extend them.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/payment-operations.md (reported line 136)May include surrounding context.

md
agent then waits on the same `runId` and same operation. If the balance remains
insufficient, leave the recovery waiting for another durable top-up; do not scan
other executing requests or create a replacement. Pending approvals require an
explicit user decision even if they originally matched Auto-Approve. An unavailable
funding check offers a read refresh; it cannot authorize payment. Existing request,
approval, and seller deadlines still apply; top-up does not extend them.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/payment-operations.md (reported line 304)May include surrounding context.

md
agent then waits on the same `runId` and same operation. If the balance remains
insufficient, leave the recovery waiting for another durable top-up; do not scan
other executing requests or create a replacement. Pending approvals require an
explicit user decision even if they originally matched Auto-Approve. An unavailable
funding check offers a read refresh; it cannot authorize payment. Existing request,
approval, and seller deadlines still apply; top-up does not extend them.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/payment-operations.md (reported line 267)May include surrounding context.

md
"maximumDebit": "7000",
  "httpRequest": {
    "requestVersion": 1,
    "url": "https://api.exa.ai/search",
    "method": "POST",
    "headers": { "content-type": "application/json" },
    "body": {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/setup.md (reported line 14)May include surrounding context.

md
When authentication is missing, start one browser OAuth flow for both account
verification and MCP authorization. The same connection page collects the email
and OTP, grants MCP access, and redirects to the host. Do not ask the
user to send an email or OTP in chat, and do not run a separate MagicPay account
setup or login flow.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/memory.md (reported line 326)May include surrounding context.

md
approval rules." Do not infer zero, manufacture an amount or currency, or
  claim that the balance call succeeded.

Then continue the user's original request without asking them to repeat it only
when the host retained that request in this same task. In a catalog-refresh
fallback, act only on the request available after refresh without claiming that
prior task context carried over. In later already-connected tasks, do not repeat

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/setup.md (reported line 236)May include surrounding context.

md
approval rules." Do not infer zero, manufacture an amount or currency, or
  claim that the balance call succeeded.

Then continue the user's original request without asking them to repeat it only
when the host retained that request in this same task. In a catalog-refresh
fallback, act only on the request available after refresh without claiming that
prior task context carried over. In later already-connected tasks, do not repeat

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instruction to always use the exact brand names MagicPay and MagicCard forces product-specific wording in user-facing replies regardless of user preference or neutral phrasing. While not directly enabling code execution or data exfiltration, it can bias outputs, reduce transparency, and steer users toward a branded payment product in sensitive financial workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.