Agora Sentinel

justpayai

justpayai · v · by

65.3
Trust Score
0
Trust Tier
danger
Badge

Score Breakdown

FactorScoreWeight
Static
0.0
15%
Permission
95.0
15%
Poison
100.0
15%
Clickfix
100.0
15%
Credential
5.0
15%
Twostage
100.0
10%
Infrastructure
100.0
5%
Typosquat
100.0
5%
Age
10.6
3%
Popularity
0.0
2%

Scan Results

STATIC — Score: 0

[CRITICAL] Cryptocurrency theft or unauthorized transfer pattern (line 28)
2. Deposit USDC → Send ≥1 USDC from a PERSONAL wallet (not exchange!) to activate
[CRITICAL] Cryptocurrency theft or unauthorized transfer pattern (line 90)
"instructions": "Send at least 1 USDC to your wallet address to activate"
[CRITICAL] Cryptocurrency theft or unauthorized transfer pattern (line 95)
**Important:** Your agent starts **unactivated**. Send ≥1 USDC (SPL token on Solana) to `walletAddress` from a **persona
[CRITICAL] Cryptocurrency theft or unauthorized transfer pattern (line 699)
> Your first deposit address is automatically saved as your **emergency recovery address**. If your API key is ever comp
[CRITICAL] Cryptocurrency theft or unauthorized transfer pattern (line 744)
Send **USDC (SPL)** on Solana to this address from a **personal wallet**. After sending, call `POST /wallet/confirm-depo
[CRITICAL] Cryptocurrency theft or unauthorized transfer pattern (line 769)
The `action` field only appears when you haven't set a withdrawal address yet. It suggests using the wallet you deposite
[CRITICAL] Cryptocurrency theft or unauthorized transfer pattern (line 843)
Withdrawals go to your saved withdrawal address. You cannot specify a different address inline — update it via `PUT /wal
[CRITICAL] Cryptocurrency theft or unauthorized transfer pattern (line 856)
1. **Withdraws your entire balance** to your **emergency address** (the wallet that sent your first deposit)
[CRITICAL] Cryptocurrency theft or unauthorized transfer pattern (line 1118)
- If you suspect your key was stolen, call `POST /wallet/panic` — this sends your entire balance to your original deposi
[CRITICAL] Cryptocurrency theft or unauthorized transfer pattern (line 1209)
# 2. Send ≥1 USDC to WALLET on Solana from a PERSONAL wallet to activate
[CRITICAL] Cryptocurrency theft or unauthorized transfer pattern (line 1249)
# 6. If API key compromised — emergency recovery (sends all funds to deposit wallet)

PERMISSION — Score: 95

[LOW] Skill appears to use network but declares no permissions

POISON — Score: 100

No findings.

CLICKFIX — Score: 100

No findings.

INFRASTRUCTURE — Score: 100

No findings.

TWOSTAGE — Score: 100

No findings.

CREDENTIAL — Score: 5

[CRITICAL] Compress sensitive files then exfiltrate (line 95)
**Important:** Your agent starts **unactivated**. Send ≥1 USDC (SPL token on Solana) to `walletAddress` from a **persona

TYPOSQUAT — Score: 100

No findings.

← Back to list