skills/steve-cooks/skills/agentpay/Gen Agent Trust Hub

agentpay

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the agentpay-cli package from the npm registry and interacts with the agent-pay.sh domain to manage payment workflows.
  • [COMMAND_EXECUTION]: The instructions include shell commands for installing software via npm and interacting with the payment API using curl for initialization and card creation.
  • [DATA_EXFILTRATION]: The skill manages sensitive API credentials and virtual card data (PAN, CVV, expiry). It documentation specifies that the CLI stores these credentials locally in the ~/.agentpay/config.json file. The network operations are directed to the vendor's own infrastructure at agent-pay.sh for the intended purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 08:47 AM
Security Audit — agent-trust-hub — agentpay