build-data-pipeline

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Solana indexing capabilities are coherent with the stated purpose, and there is no black-box installer or obvious malware behavior. The main concern is telemetry: the skill reads a locally configured convexUrl and posts usage events to whatever host is configured, creating a moderate external data-flow risk. A secondary concern is the example that places a Helius API key in a URL query string, which is functional but exposure-prone. Overall this is not fundamentally incompatible with its purpose, but the telemetry design and key-handling example make it riskier than a purely local documentation/build skill.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Apr 14, 2026, 03:16 PM
Package URL
pkg:socket/skills-sh/sendaifun%2Fsolana-new%2Fbuild-data-pipeline%2F@a2dd2c9f6c94507d07492146ab2595c6ea19fc3c