moonpay-commerce

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and the CLI provenance appears legitimate via MoonPay’s official npm package and docs, so this is not a clear supply-chain or credential-harvesting lure. However, it grants an AI agent autonomous real-world purchasing and on-chain payment capability, forwarding buyer PII through an external CLI and enabling irreversible financial actions; that makes the skill high risk even though the data flows appear consistent with its stated commerce purpose.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Mar 21, 2026, 10:27 PM
Package URL
pkg:socket/skills-sh/moonpay%2Fskills%2Fmoonpay-commerce%2F@eda752b9a8995461ab37892d1302c44490cec543