pnp-markets-solana

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherent with its stated goal of enabling permissioned Solana-based prediction markets and autonomous-agent workflows. The primary security concerns are (1) the proxy-assisted settlement flow introducing an external trust boundary, (2) handling of sensitive wallet credentials (PRIVATE_KEY) in client deployments, and (3) potential data exposure from social-media integrations. If the proxy settlement usage is optional and clearly documented with strong privacy guarantees and user consent, and if credential handling follows best practices (environment isolation, key management, least privilege), the overall footprint remains within an acceptable risk envelope for a developer-focused tooling skill. The footprint does not indicate credential harvesting, hidden data exfiltration, or supply-chain threats beyond standard wallet-key usage and a documented external resolution step.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 03:42 AM
Package URL
pkg:socket/skills-sh/pnp-protocol%2Fsolana-skill%2Fpnp-markets-solana%2F@74ad1dee784ce4e5280a92cb1e88cfc6333bddd1