fluxa agentic checkout

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its stated purpose, but that purpose itself is high risk. It enables autonomous real-world purchases, processes full payment credentials, and retains sensitive checkout artifacts locally. No clear credential-harvesting endpoint or deceptive installer is shown, so this is not confirmed malware, but it is a high-risk skill that should require strict user approval and careful handling of stored artifacts and secrets.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
May 14, 2026, 12:39 AM
Package URL
pkg:socket/skills-sh/fluxa-agent-payment%2Ffluxa-ai-wallet-mcp%2Ffluxa-agentic-checkout%2F@6b8524171ca020e0b92f228edaa9d35dd268d009