moonpay-x402
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the
mpCLI tool, which is a vendor-provided utility for blockchain interactions and API requests. The use of this command is documented and limited to the stated purpose of facilitating paid requests. - [EXTERNAL_DOWNLOADS]: The skill interacts with
agents.moonpay.com, a domain owned and managed by the skill's author (MoonPay). This is a legitimate service endpoint used for the skill's intended functionality. - [DATA_EXFILTRATION]: The skill's ability to send requests to arbitrary URLs via the
--urlparameter is the primary intended function and does not include any automated or hidden logic for unauthorized data collection.
Audit Metadata