paythefly
Fail
Audited by Snyk on Jun 16, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). The link points to a GitHub repository from an unknown account (not an established vendor) that supplies a package installed via npx (which executes remote code), so although it’s not a direct .exe download it is a suspicious source for executable code with limited provenance.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly for creating crypto payment and withdrawal links for an app — a specific capability to move funds (payments and withdrawals) on blockchain/crypto. This is direct financial execution (crypto transactions), so it meets the criteria for risk=1.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata