SunSwap DEX Trading

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The described skill legitimately provides automated swap tooling for SunSwap on TRON but requires storing a raw TRON_PRIVATE_KEY in environment variables and encourages automation that can perform irreversible on-chain transactions. Because no implementation code was supplied, we cannot assert whether the scripts leak keys or phone home; however, the design choices (env private key, unpinned npm installs, AI-driven --execute) present real supply-chain and operational risks. Recommended mitigations before use with high-value keys: 1) require an audit of the actual JS scripts and dependency lockfile, 2) use hardware wallets or delegated signing services rather than raw private keys, 3) pin and verify dependency checksums, 4) enforce interactive human confirmation or multi-sig for significant transfers, and 5) run in a least-privilege environment (ephemeral/test wallets for automation). Treat the package as medium risk until code and dependencies are audited.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 3, 2026, 03:22 AM
Package URL
pkg:socket/skills-sh/BofAI%2Fskills%2Fsunswap-dex-trading%2F@9d6bdc80f0713e02a9773442e48e29da7ad55b6a