simmer-x402

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with its stated x402-payment purpose and uses an official-looking SDK path, but it enables autonomous cryptocurrency spending and requires direct private-key handling. There is no clear evidence of credential theft or covert exfiltration, yet the financial autonomy and broad paid-fetch scope make it high security risk for an agent environment.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Mar 15, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/spartanlabsxyz%2Fsimmer-sdk%2Fsimmer-x402%2F@98184ffb56137272b92f11e1db26a64cf2f80084