one-click-token-launch
Audited by Socket on Oct 8, 2026
4 alerts found:
Securityx3AnomalySUSPICIOUS: the skill's stated purpose matches its crypto-launch capabilities, but it enables autonomous real-world financial actions and routes token launch data through several third-party crypto services. The install path itself looks mostly documentation-grade rather than overtly malicious, yet the overall risk is high because the skill can create and buy tokens on-chain, upload user content externally, and trigger irreversible transactions.
The code has a significant key-handling concern: it transmits a generated mint private key to a remote API. This may be part of the intended token-creation protocol, but the API must be trusted. The API also supplies transaction data to a wallet-signing command without local validation. No clear evidence of deliberate malware is present; use only with a trusted, verified API endpoint and wallet CLI.
The code performs ordinary token-launch and transaction-confirmation operations, but it sends the newly generated mint private key to a remote API and submits API-provided transaction data for wallet signing without local validation. These are significant trust and key-handling risks. The fragment alone does not establish malicious intent; verify the configured API and whether disclosure of the mint secret is required and safe.
No clear malware behavior is present. However, the code blindly submits an API-provided transaction to a wallet signing and broadcast operation. If the API or its response is compromised or untrusted, it could supply unintended transaction instructions. Validate the transaction contents against the requested launch before signing.