meteora

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/bonding-curve/trade.ts

This module appears to be a Solana mainnet bonding-curve trading/monitoring script. It does not show clear signs of intentional malware (no obfuscation, no dynamic execution, no suspicious network destinations, no exfiltration). However, it is high-impact operationally: it reconstructs a signing Keypair from process.env.WALLET_SECRET_KEY and auto-executes a real on-chain buy on module run using the configured POOL_ADDRESS. The main risks are credential-handling impact and unintended transaction execution rather than demonstrated malicious payloads.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Aug 4, 2026, 12:37 AM
Package URL
pkg:socket/skills-sh/JustaName-id%2Fcryptoskills%2Fmeteora%2F@0e977a790c52f071afe03980d1c3ebbf3cc5425021805e46b1f1ee34cc5067c6
Security Audit — socket — meteora