pay-for-service

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is coherent with its stated purpose of paying x402 endpoints, but it combines runtime installation of an unpinned npm CLI, credential forwarding to that CLI, and real-money payment execution to arbitrary URLs. The footprint is proportionate yet high-risk, so this is not clearly malicious, but it should be treated as a sensitive financial/payment skill with meaningful supply-chain and credential-trust concerns.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
Apr 23, 2026, 02:41 PM
Package URL
pkg:socket/skills-sh/agnicpay%2Fagnic-wallet-skills%2Fpay-for-service%2F@852d44b905d22aa8dc3f7f26beb906e03ce7d8f3