tap-to-pay-on-iphone

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The resource file references/regions-and-psps.md contains links to https://www.sparkasse-pos.de/ios.html. This specific URL and domain are currently blacklisted by reputation scanners as malicious.
  • [REMOTE_CODE_EXECUTION]: The skill provides numerous links to external SDK repositories for payment processing integration. Examples include github.com/sumup/sumup-ios-sdk, github.com/Fiserv/TTPPackage/, and github.com/TapPay/tappay-ios-t2p-sdk. While these are associated with well-known financial services, the presence of blacklisted URLs within the skill's reference library increases the risk of supply chain redirection to malicious payloads.
  • [METADATA_POISONING]: The primary skill file SKILL.md has been flagged by file reputation scanners. This detection is consistent with a file containing or referencing known malicious infrastructure, which poses a risk to agents processing the documentation.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 12:20 PM
Security Audit — agent-trust-hub — tap-to-pay-on-iphone