goldrush-x402

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/ai-agents.md

The code/documentation fragment is not malicious per se but presents significant security and supply-chain concerns due to wallet-based autonomous access and exposure of wallet private keys in sample code. adoption without robust secret management, auditing, and control planes could lead to credential leakage, unauthorized spending, and abuse. Treat as high-risk documentation with potential for real-world misuse if integrated without proper secret handling and monitoring.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 4, 2026, 07:42 PM
Package URL
pkg:socket/skills-sh/covalenthq%2Fgoldrush-agent-skills%2Fgoldrush-x402%2F@83c7d84855b1f47b47149f5a2e72ebd3f989851b