one-click-token-launch

Warn

Audited by Socket on Apr 15, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SUMMARY.md

Conclusion: The concept describes a powerful, high-privilege token-launch platform with extensive external integrations and potential supply-chain risks. Without executable code, definitive security validation is not possible. Main risks include data handling of user inputs to IPFS/metadata, client-side key material handling, unverifiable TEEs, rapid token deployment via one-click workflows, and reliance on external adapters and endpoints. Obtain the actual source files to perform concrete source-to-sink analysis, verify cryptographic material handling, and assess dependency integrity and signing trust.

Confidence: 61%Severity: 60%
SecurityMEDIUM
SKILL.md

The skill’s capabilities largely match its stated purpose, but that purpose is itself high risk: it enables an AI agent to launch tokens, upload metadata, and execute irreversible on-chain financial actions through multiple third-party services. I do not see clear credential theft or covert exfiltration, so this is not confirmed malware, but it is a suspicious/high-risk skill because of autonomous real-world financial actions, broad external dependencies, and multi-endpoint data flow.

Confidence: 82%Severity: 76%
Audit Metadata
Analyzed At
Apr 15, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fone-click-token-launch%2F@00886980033e504875555f6bbf9b2f8c27dba2d6