Solana Squads Upgrade

Warn

Audited by Socket on Jul 27, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s Solana/Squads capabilities align with its stated purpose, but it asks users to pass a keypair into externally executed GitHub Action code and has ambiguous action provenance due to owner/reference mismatch. That makes this a meaningful supply-chain and credential-forwarding risk, though not confirmed malware.

Confidence: 86%Severity: 72%
AnomalyLOW
examples/anchor-upgrade.yml

The workflow YAML contains no direct malicious code or obvious credential exfiltration logic, but it is a supply-chain risk hotspot: it delegates a privileged Solana program upgrade to a third-party GitHub Action while passing high-value secrets (RPC URL, multisig, keypair). Because the action is invoked via a tag rather than a pinned digest and its internals are not visible here, the key security concern is potential malicious or compromised action behavior leading to unauthorized upgrades and/or secret misuse.

Confidence: 70%Severity: 60%
Audit Metadata
Analyzed At
Jul 27, 2026, 07:10 AM
Package URL
pkg:socket/skills-sh/widnyana%2Feyay-toolkits%2Fsolana-squads-upgrade%2F@fcd9bd68691f967f2762ba0bb52e33b236ecbef4
Security Audit — socket — Solana Squads Upgrade