pump-ai-agents

Warn

Audited by Socket on Jul 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s general crypto/Pump SDK purpose is coherent, but it goes beyond passive agent guidance by having the agent install and run an unverified MCP server via unpinned `npx -y`. Because the external CLI provenance was not clearly verified and such tooling may receive wallet or RPC credentials and enable financial actions, the install-trust and scope risks are disproportionate to a documentation-style skill.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Jul 9, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/Solizardking%2Fsolana-clawd%2Fpump-ai-agents%2F@229dcc5540209d1d68cc30ad0f6a68507adce0c10c44e527fa931eb96989b791
Security Audit — socket — pump-ai-agents