x402

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely coherent with its stated purpose and uses official install sources, so it does not look malicious. However, it enables autonomous financial actions and forwards signed payment data to a hosted facilitator, and one documentation claim about 'no API keys' overstates the CDP production path. Overall this is a legitimate but high-impact payment skill with meaningful operational risk.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
May 8, 2026, 06:54 PM
Package URL
pkg:socket/skills-sh/aomi-labs%2Fskills%2Fx402%2F@6d2bf5edbbfa860d8a65ebc19063beaf29ed7586