ovra-agentic-payments
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent and uses official Ovra endpoints, but it grants an AI agent the ability to perform autonomous financial transactions and retrieve tokenized payment credentials. This is not confirmed malware, yet it is a high-risk payment automation skill because real-world spending can occur without explicit per-action human approval.
Confidence: 84%Severity: 78%
Audit Metadata