create-paid-skill
Warn
Audited by Snyk on Mar 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill explicitly instructs agents to fetch and parse SKILL.md from public sources (e.g., "Direct URL", GitHub repos, skills.sh) and to read OpenAPI specs via generateFromOpenAPI(), meaning it ingests untrusted, user-provided web content that the agent will read and use to decide actions (see "Step 6: Conversions" and "Step 7: Publishing Options / Direct URL" and the note that "the body is what an AI agent actually reads").
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly payment-native: it defines payment fields (payment.networks, asset, payTo, payToEvm), requires prices for endpoints (priceUsdc), describes the x402 payment protocol step-by-step (402 responses, signing transfers, X-PAYMENT header), and includes concrete code examples (x402Fetch with stellarSecret) and wallet/address formats. These are specific tools/instructions to initiate and settle crypto payments (USDC on Stellar/Base) and thus provide the agent with direct financial execution capabilities rather than a generic API description.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata