pump-fun

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches Solana/pump.fun trading, but the footprint is broader than necessary: it installs an unverifiable binary, adds other skills transitively, and sends installation telemetry with device-derived identifiers to third-party endpoints. The financial-action capability is inherently high impact, and the install/data-flow model is not proportionate to a simple trading helper.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:28 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fpump-fun%2F@7003416f82e634f32c1bb9741fc22d4cc74c6d4e