lighter
Audited by Socket on Sep 14, 2026
2 alerts found:
Anomalyx2BENIGN for purpose alignment and data flow: the skill's capabilities match a Lighter trading integration, and data appears to go to official Lighter-controlled endpoints. Security risk is still meaningful because it grants an agent high-impact financial actions and uses sensitive trading keys, but this is not evidence of malware or credential theft from the provided skill text.
No clear intentional malware or covert data theft is present. The code is a trading/API integration with expected private-key handling and transaction submission. Security concerns are the runtime pip installation and the lack of validation for user-configurable API URLs, which could redirect authenticated requests and expose credentials or authorize unintended transactions if configuration is compromised. The incomplete ending may also cause a functional error.