tap-to-pay-on-iphone
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The resource file
references/regions-and-psps.mdcontains links tohttps://www.sparkasse-pos.de/ios.html. This specific URL and domain are currently blacklisted by reputation scanners as malicious. - [REMOTE_CODE_EXECUTION]: The skill provides numerous links to external SDK repositories for payment processing integration. Examples include
github.com/sumup/sumup-ios-sdk,github.com/Fiserv/TTPPackage/, andgithub.com/TapPay/tappay-ios-t2p-sdk. While these are associated with well-known financial services, the presence of blacklisted URLs within the skill's reference library increases the risk of supply chain redirection to malicious payloads. - [METADATA_POISONING]: The primary skill file
SKILL.mdhas been flagged by file reputation scanners. This detection is consistent with a file containing or referencing known malicious infrastructure, which poses a risk to agents processing the documentation.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata