Back to skill

Security audit

Alipay Pay For 402 Service

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Alipay 402 payment workflow with sensitive payment behavior, but the reviewed artifacts keep the behavior tied to that purpose and require user-facing checks before key actions.

Install only if you are comfortable using an external Alipay CLI for 402 purchases. Review the merchant, amount, and authorization prompts before paying, and avoid submitting feedback text that contains secrets or unrelated personal information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill adds a `problem-feedback` workflow that sends conversation-derived issue details to an external CLI endpoint, which is outside the narrowly declared purpose of handling 402 payment execution. This expands the data-sharing surface and can transmit user/context information without the manifest clearly declaring that secondary reporting behavior.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The instructions direct the agent to invoke another skill, `alipay-authenticate-wallet`, which broadens behavior beyond the declared 402 payment-handling scope. Cross-skill invocation can trigger additional privileges, data flows, or actions that the user and policy reviewer did not expect from this skill alone.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.