payram-self-hosted-payment-gateway
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s overall purpose is coherent for a self-hosted crypto gateway, but its footprint is high-risk: it uses a remote one-line installer whose provenance does not match the cited official install evidence, asks operators to place wallet private keys into server-hosted software, and expands trust to another skill and a cloned MCP repo. This looks more like risky deployment guidance than confirmed malware, but the install-trust and credential-handling issues are significant.
Confidence: 84%Severity: 81%
Audit Metadata