a2a-wallet

Warn

Audited by Socket on Mar 31, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
INSTALL.md

The code snippet demonstrates a common but high-risk installer pattern: executing a remotely fetched script without integrity checks. This introduces potential supply-chain risk if the remote script is malicious or compromised. Users should prefer verified releases with hash/signature verification or package managers with pinned integrity when installing such software.

Confidence: 59%Severity: 62%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and uses an official same-org distribution path, so it does not look like disguised malware. However, it gives an AI agent high-risk cryptocurrency and wallet capabilities, includes access to plain-file local keys, and uses an unpinned curl|sh installer; this makes it a high-security-risk financial skill even without clear malicious intent.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 31, 2026, 01:46 AM
Package URL
pkg:socket/skills-sh/planetarium%2Fa2a-x402-wallet%2Fa2a-wallet%2F@1b5b03560e7e75cd09a4567b8d88450f51d3e432