agent-payment-x402

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the "agentwallet-sdk" package from the official NPM registry via npx. The documentation explicitly recommends version pinning to mitigate supply-chain risks.
  • [COMMAND_EXECUTION]: Executes the wallet SDK as a subprocess. The implementation example demonstrates secure coding practices, including strict input validation and restricted environment variable forwarding.
  • [CREDENTIALS_UNSAFE]: The skill manages private keys but avoids hardcoding by instructing users to use environment variables, following standard security practices for secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:08 AM
Security Audit — agent-trust-hub — agent-payment-x402