agent-checkouts

Warn

Audited by Socket on Jul 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is broadly consistent with its stated purpose and appears to use official Crossmint API flows, not a third-party interception service. The main risk is not hidden malware but the combination of a stored production server key, transmission of buyer/order data, and the ability to execute irreversible real-money purchases; this makes it high-impact and medium-high security risk even though intent appears legitimate.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Jul 10, 2026, 04:37 PM
Package URL
pkg:socket/skills-sh/Crossmint%2Fagent-checkouts-skill%2Fagent-checkouts%2F@b2cf07f7a8e8c1f824bafddfffb504f289997380
Security Audit — socket — agent-checkouts