allium-x402

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s blockchain-data purpose broadly matches its capabilities, but trust is weakened by a remote curl|sh installer, explicit HTTP install text, runtime fetching of additional skills, and credential/payment handling through an external CLI. This looks more like a risky same-org distribution pattern than confirmed malware, but the install and transitive-instruction model are not proportionate to a low-risk data-query skill.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 21, 2026, 10:26 PM
Package URL
pkg:socket/skills-sh/moonpay%2Fskills%2Fallium-x402%2F@219e00d3cec04280201b1ebb82f6174439dd643e