SunPump Meme Token Toolkit

Warn

Audited by Socket on Jun 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated purpose and mostly uses proportionate tooling, but it enables high-impact financial transactions, forwards wallet credentials to an external CLI, and includes transitive skill installation. This looks more like a risky crypto-trading skill than overt malware; the main concerns are autonomy and credential/trust scope, not hidden exfiltration.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Jun 4, 2026, 03:52 AM
Package URL
pkg:socket/skills-sh/BofAI%2Fskills%2Fsunpump-meme-token-toolkit%2F@cb1990d5571aec3bf833cef519d3675dc8d1e3e7
Security Audit — socket — SunPump Meme Token Toolkit