pay-for-service

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned, but its purpose is inherently high impact: it lets the agent trigger real USDC payments and send request data to arbitrary paid endpoints through a third-party CLI. The pinned npm source lowers supply-chain concern versus an unknown binary, but the autonomous payment capability and broad outbound scope make this a high security-risk skill rather than benign documentation.

Confidence: 83%Severity: 78%
Audit Metadata
Analyzed At
May 7, 2026, 04:28 AM
Package URL
pkg:socket/skills-sh/coinbase%2Fagentic-wallet-skills%2Fpay-for-service%2F@5482408616efb271ce08f2e26c90061bf027c7f1