moonpay-x402

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and uses an official same-org CLI and endpoint, so it does not look like credential harvesting or covert exfiltration. However, it explicitly enables autonomous real-world financial actions by spending from a local crypto wallet, which makes the overall skill high risk despite otherwise coherent install trust and data flow.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 21, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/moonpay%2Fskills%2Fmoonpay-x402%2F@d3fd87aaef803b1442e567f11d09454243f855d0