light-token-client

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent developer-focused toolkit for Light Token client interactions with Solana, with legitimate credential requirements (API_KEY and a local keypair) and standard SDK usage. The primary security concerns stem from installation via a GitHub-based npx command (unverifiable provenance) and the handling of API keys/local keypairs in examples. Overall, the footprint is BENIGN with MEDIUM risk due to supply-chain and credential exposure considerations. Recommend using pinned, verifiable installations (official registries or checksums) and ensuring API keys/keypairs are never logged or transmitted outside secure environments.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 06:32 PM
Package URL
pkg:socket/skills-sh/Lightprotocol%2Fskills%2Flight-token-client%2F@3214a1f5e2ee2d6353f6ac69340373137dde8c3f