alchemy

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The direct Alchemy API-key path is coherent and largely benign, with official endpoints and proportionate credentials. However, the skill also pushes optional x402/MPP payment modes that require external tooling and enable autonomous payment actions, creating medium risk and a broader trust boundary than a basic blockchain-data skill. No clear malware or credential theft behavior is evident, but the install and payment footprint is larger than necessary for many read-only use cases.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:32 AM
Package URL
pkg:socket/skills-sh/BankrBot%2Fskills%2Falchemy%2F@1cd2b2c45bab699257351c11f815279ab9aa5ac0