moonpay-swap-tokens

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and uses a same-org CLI from npm, but it grants an AI agent high-impact autonomous trading/bridging powers and depends on external routing infrastructure. This is not confirmed malware, yet it is a high-risk financial-action skill that should require explicit user approval per transaction.

Confidence: 88%Severity: 83%
Audit Metadata
Analyzed At
Mar 21, 2026, 10:27 PM
Package URL
pkg:socket/skills-sh/moonpay%2Fskills%2Fmoonpay-swap-tokens%2F@8fa56262414285cde8552d39a0b472ad84debdaf