pay-via-agent-wallet

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned for paid API access, but it grants an agent the ability to autonomously spend USDC, move funds, and query third-party services based on untrusted external content. There is no strong sign of credential theft or covert exfiltration, yet the real-world financial authority and broad external-call surface make the skill high risk.

Confidence: 88%Severity: 81%
Audit Metadata
Analyzed At
May 11, 2026, 11:41 AM
Package URL
pkg:socket/skills-sh/circlefin%2Fskills%2Fpay-via-agent-wallet%2F@f449cd058331fa5b8292594e41efcfb815343d38