fluxa-agent-wallet

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core wallet/payment functionality aligns with the stated purpose and uses mostly same-brand infrastructure, so this is not confirmed malware. However, it grants an AI agent high-impact financial capabilities, exposes full card details, supports arbitrary x402/external service interaction, and extends trust to third-party monetized skills/APIs, making the overall skill high risk even with user-approval language.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 19, 2026, 04:43 PM
Package URL
pkg:socket/skills-sh/fluxa-agent-payment%2Ffluxa-ai-wallet-mcp%2Ffluxa-agent-wallet%2F@ccdbec754b8cc77a6b5af3a7b281990410483e50