raydium

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core Raydium read/write behavior fits the stated purpose, but the skill’s footprint is broader than necessary: it installs extra global skills, fetches a non-registry binary from a third-party GitHub release path, and sends install telemetry/device-derived identifiers to external endpoints. Because it also enables financial transactions, the overall risk is high even without confirmed malware.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:27 AM
Package URL
pkg:socket/skills-sh/MigOKG%2Fplugin-store%2Fraydium%2F@7f6c17eb5d5648db2de66e3ab9dd0124c4169b4c