alchemy

Warn

Audited by Socket on Sep 24, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/x402/overview.md

The fragment is gateway documentation rather than executable code, so it provides no evidence of malware or actual key exfiltration. Its instruction to suppress an authentication alternative and its request for an existing private key are suspicious and unsafe if interpreted as asking a user to disclose the key. Keep private keys local and verify the package and payment details before use.

Confidence: 96%Severity: 57%
AnomalyLOW
references/mpp/payment.md

No evidence of intentional malware, data theft, backdoors, or obfuscated malicious behavior is present. The examples implement payment functionality as described. The /api/create-spt endpoint is insecure if exposed without authentication, authorization, strict input validation, amount/currency limits, and rate limiting because it uses a server-side Stripe secret to process client-controlled payment requests. The private-key example must remain strictly server-side and never be bundled into client code.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 24, 2026, 04:47 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fskills%2Falchemy%2F@cddbed80fc1eb07a6df3a5cf0f8d8e06ceeac0f05ac0de797acf83adf86807cf
Security Audit — socket — alchemy