paythefly

Fail

Audited by Snyk on Jun 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). The link points to a GitHub repository from an unknown account (not an established vendor) that supplies a package installed via npx (which executes remote code), so although it’s not a direct .exe download it is a suspicious source for executable code with limited provenance.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly for creating crypto payment and withdrawal links for an app — a specific capability to move funds (payments and withdrawals) on blockchain/crypto. This is direct financial execution (crypto transactions), so it meets the criteria for risk=1.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 16, 2026, 01:05 AM
Issues
2
Security Audit — snyk — paythefly