fluxa-agent-wallet

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill appears purpose-aligned and uses mostly coherent first-party endpoints, but it grants an AI agent high-impact financial capabilities and introduces transitive trust through payment-enabled skill discovery. This is best classified as suspicious/high-risk rather than malware: not because of obvious exfiltration, but because autonomous payment execution and downstream skill use materially raise security exposure.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Mar 13, 2026, 12:07 PM
Package URL
pkg:socket/skills-sh/FluxA-Agent-Payment%2FFluxA-AI-Wallet-MCP%2Ffluxa-agent-wallet%2F@dec1e3b2ea3be5f31fb9e367997632c6db4ca2a7