drift-sdk

Fail

Audited by Socket on Feb 20, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The documentation describes a powerful trading tool that requires raw private keys and an RPC URL. The file itself is not evidence of malicious code, but the absence of implementation code is a critical blind spot: it is impossible to verify whether signing is local or whether the private key may be exfiltrated. Because high-impact on-chain actions are supported and no secure key-handling or external-signer options are documented, this package poses a notable supply-chain/security risk until the code is audited. Treat as potentially dangerous for real funds; require code review, isolated testing with ephemeral keys, and prefer hardware/external signing before usage.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 20, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/alsk1992%2Fcloddsbot%2Fdrift-sdk%2F@cdad11d07070c2e0fdb7cbe3246c2634a23441e7