one-click-token-launch

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SUMMARY.md

Conclusion: The concept describes a powerful, high-privilege token-launch platform with extensive external integrations and potential supply-chain risks. Without executable code, definitive security validation is not possible. Main risks include data handling of user inputs to IPFS/metadata, client-side key material handling, unverifiable TEEs, rapid token deployment via one-click workflows, and reliance on external adapters and endpoints. Obtain the actual source files to perform concrete source-to-sink analysis, verify cryptographic material handling, and assess dependency integrity and signing trust.

Confidence: 61%Severity: 60%
Audit Metadata
Analyzed At
May 8, 2026, 03:41 PM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fone-click-token-launch%2F@fb911f6e741e574b378e680538a2d260a7d0afd6