alby-bitcoin-payments-cli-skill

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities match its stated Bitcoin wallet purpose, and the CLI appears to be distributed through an expected same-org/npm path rather than an unknown binary. However, it handles raw wallet-control secrets and enables autonomous money movement, so the security risk is medium-high even without evidence of malicious intent.

Confidence: 85%Severity: 66%
Audit Metadata
Analyzed At
Mar 16, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/getalby%2Falby-cli-skill%2Falby-bitcoin-payments-cli-skill%2F@cdcaf5cdb0a18093a49185ac4e1562973308434f