ovra-agentic-payments

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent and uses official Ovra endpoints, but it grants an AI agent the ability to perform autonomous financial transactions and retrieve tokenized payment credentials. This is not confirmed malware, yet it is a high-risk payment automation skill because real-world spending can occur without explicit per-action human approval.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 9, 2026, 12:07 AM
Package URL
pkg:socket/skills-sh/Ovra-Labs%2Fovra-skills%2Fovra-agentic-payments%2F@f4d4763ec40b57e32dcbe77da0bd9e68a47afe3b