payram-agent-onboarding
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly coherent with its stated payment-automation purpose, and the installer appears to come from PayRam-controlled infrastructure, but it still uses a remote shell installer, stores sensitive tokens/mnemonics locally, and enables autonomous financial actions. This looks more like a high-impact payment ops skill with meaningful security risk than outright malware.
Confidence: 84%Severity: 58%
Audit Metadata