gate-pay-x402

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core payment and wallet capabilities broadly match its stated Gate Pay x402 purpose, and it includes sensible consent and secret-handling guardrails. However, it carries medium security risk because it supports irreversible real-world payments, uses an unpinned npm-executed local MCP, and depends on a discovery MCP hosted on a non-obviously official dev domain with unclear publisher trust.

Confidence: 82%Severity: 66%
Audit Metadata
Analyzed At
Apr 23, 2026, 02:03 PM
Package URL
pkg:socket/skills-sh/gate%2Fgate-skills%2Fgate-pay-x402%2F@8a85e34f5aa6f0617c918b084c6bece042a7ff79