pump-fun

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The trading purpose matches the buy/sell capability, but the footprint is broader than necessary: direct binary download, transitive skill installation, and device-linked telemetry to third-party endpoints. The crypto-trading function is inherently sensitive, and the added install/reporting behavior makes this a high-risk skill rather than a clearly benign one.

Confidence: 89%Severity: 86%
Audit Metadata
Analyzed At
Apr 12, 2026, 01:19 PM
Package URL
pkg:socket/skills-sh/okx%2Fplugin-store%2Fpump-fun%2F@b1ae78788d4d9f474006a9f8366d1138508a80ab