pump-token-lifecycle

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent in subject matter, but it enables autonomous cryptocurrency actions—token creation, trading, migration, and fee collection—which are inherently high risk for an AI agent. Install trust is mixed: the referenced SDK appears to be a community package from a personal GitHub account, not the official Pump package, though distribution is via npm rather than an opaque binary installer. No direct credential theft or exfiltration is evident, but the combination of real-money blockchain operations and reliance on a non-official SDK makes this a high security-risk skill.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
May 7, 2026, 11:55 PM
Package URL
pkg:socket/skills-sh/nirholas%2Fpump-fun-sdk%2Fpump-token-lifecycle%2F@efd03f435d1ac8bf28e3fc6bf2f9a741e36eda3b
Security Audit — socket — pump-token-lifecycle