x402-payment

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
uninstall.sh

This fragment appears to be an installer or reinstall instruction. It does not itself demonstrate malware, but it uses the security-sensitive curl-pipe-to-shell pattern and an unpinned remote script, which creates substantial supply-chain and remote-code-execution risk if the repository or transport content is compromised. Review and verify install.sh, pin a trusted commit or release, and validate integrity before execution.

Confidence: 94%Severity: 68%
AnomalyLOW
README.md

The fragment is documentation, not evidence of malicious code. No direct malware indicators are present, but the curl-to-sh installation pattern is a significant supply-chain and execution risk because it runs mutable remote code without local inspection or cryptographic verification. Review the installer and exact package artifacts before use, and prefer downloading, auditing, and pinning the script and dependencies rather than piping remote content directly to sh.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:06 PM
Package URL
pkg:socket/skills-sh/bofai%2Fskills%2Fx402-payment%2F@c6d2237307d9a1f077272e843be0709fb3ee623ed5000ebb8335dcb1795536f8
Security Audit — socket — x402-payment