SunPump Meme Token Toolkit

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and capabilities are internally consistent: this is a SunPump/SunSwap trading and token-launch skill using an official-looking npm CLI and official SUN ecosystem docs. The main risk is not covert malware but that it gives an AI agent the ability to perform irreversible financial actions and create on-chain assets, while also relying on transitive skill trust and forwarding wallet secrets to an external CLI. Overall: suspicious/high-risk as an AI agent skill, but not confirmed malicious.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:05 PM
Package URL
pkg:socket/skills-sh/bofai%2Fskills%2Fsunpump-meme-token-toolkit%2F@0018cb53cc421af91426e95886fcf490068e5923
Security Audit — socket — SunPump Meme Token Toolkit