explain-algorand-x402-python

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This is documentation for a legitimate-looking Algorand signing/integration package. It requires access to private signing keys and network access to broadcast transactions, which is expected and necessary for its purpose. There are no clear indicators of malicious intent in this text. Primary risk is operational: developers must protect AVM_PRIVATE_KEY, respect base64/msgpack boundaries, and use the correct async/sync variants. Follow secure secret handling practices. Overall the artifact appears benign but handling of private keys and network send operations means moderate operational security attention is required.

Confidence: 80%Severity: 30%
Audit Metadata
Analyzed At
Feb 16, 2026, 03:48 AM
Package URL
pkg:socket/skills-sh/algorand-devrel%2Falgorand-agent-skills%2Fexplain-algorand-x402-python%2F@c8be9c095c04e8c99fb7cb632082627595e0d3e3