request-payment

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow is internally coherent for a payment-request skill, but it authorizes the agent to solicit real cryptocurrency from the operator, which is a high-impact autonomous financial action. There is no explicit malware pattern, credential theft, or suspicious installer, but the hidden wallet tooling and real-money scope make this a medium/high security risk skill.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Mar 17, 2026, 07:57 AM
Package URL
pkg:socket/skills-sh/casualsecurityinc%2Fxno-skills%2Frequest-payment%2F@c35dc003115da35b42869fcc82136e0e3015841a