payram-self-hosted-payment-gateway

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent for a self-hosted crypto gateway, but its footprint is high-risk: it uses a remote one-line installer whose provenance does not match the cited official install evidence, asks operators to place wallet private keys into server-hosted software, and expands trust to another skill and a cloned MCP repo. This looks more like risky deployment guidance than confirmed malware, but the install-trust and credential-handling issues are significant.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
May 17, 2026, 04:10 AM
Package URL
pkg:socket/skills-sh/payram%2Fpayram-mcp%2Fpayram-self-hosted-payment-gateway%2F@5a79b2c70dbbe1902c1369c4791b1b4abb5add5d
Security Audit — socket — payram-self-hosted-payment-gateway