payram-no-kyc-crypto-payments

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment is largely coherent with a self-hosted, no-KYC payment gateway concept but carries a significant supply-chain risk due to a download-and-execute deployment pattern (curl ... | bash) from an external domain. This pattern, combined with ambiguous key management and reliance on a self-hosted environment, makes the setup susceptible to tampering, credential exposure during initial install, or supply-chain compromise. Treat as SUSPICIOUS with HIGH vigilance until installer integrity, provenance, and post-install security controls are verifiably enforced.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 08:27 AM
Package URL
pkg:socket/skills-sh/payram%2Fpayram-mcp%2Fpayram-no-kyc-crypto-payments%2F@064ae7d50553f5c5416726175cce5b52455e64df