x402-payment

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned for crypto payments, but it carries high inherent risk because it authorizes autonomous real-world financial transactions, can auto-approve token allowances, targets arbitrary user-provided endpoints, and references another skill/toolchain for setup. I do not see clear credential theft or deceptive exfiltration, so this is not confirmed malware, but it is a high-risk payment skill that should require strict user approval per transaction.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:26 AM
Package URL
pkg:socket/skills-sh/BofAI%2Fskills%2Fx402-payment%2F@ae264315decc03e71b069bf1b0c8fb6a75a8ce72