fluxa-agent-wallet-via-api

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill incorporates strong security controls for on-chain financial operations. All USDC payouts and the creation of spending mandates require explicit user authorization through the FluxA Wallet web interface. This prevents the agent from performing unauthorized transfers without direct user consent.\n- [SAFE]: Implements 'intent mandates' for x402 payments. Users pre-approve spending limits including budget and time duration. The FluxA Wallet API enforces these constraints server-side, ensuring autonomous API payments stay within user-defined boundaries.\n- [COMMAND_EXECUTION]: Documentation includes standard utility commands. Examples use curl for REST API interactions. Mentions a vendor-provided CLI tool fluxa-wallet for refreshing authentication tokens.\n- [EXTERNAL_DOWNLOADS]: The skill interacts with the vendor's infrastructure and well-known service providers. Network requests are directed to fluxapay.xyz and Cloudflare Workers (gmlgtm.workers.dev). These calls are authenticated via JWT and are necessary for the skill's financial management functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 12:07 AM