agent-payment-x402
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the "agentwallet-sdk" package from the official NPM registry via npx. The documentation explicitly recommends version pinning to mitigate supply-chain risks.
- [COMMAND_EXECUTION]: Executes the wallet SDK as a subprocess. The implementation example demonstrates secure coding practices, including strict input validation and restricted environment variable forwarding.
- [CREDENTIALS_UNSAFE]: The skill manages private keys but avoids hardcoding by instructing users to use environment variables, following standard security practices for secret management.
Audit Metadata