payram-payment-integration

Fail

Audited by Gen Agent Trust Hub on Feb 21, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • EXTERNAL_DOWNLOADS (HIGH): The skill directs the agent or user to clone a repository from an untrusted source (github.com/PayRam). Evidence: git clone https://github.com/PayRam/payram-helper-mcp-server.- COMMAND_EXECUTION (HIGH): Instructions include running yarn install and yarn dev on the unvetted external code immediately after cloning, which can lead to arbitrary code execution. Evidence: cd payram-helper-mcp-server && yarn install && yarn dev.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 21, 2026, 01:48 PM