4CHAD
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill bundle is designed for autonomous AI agents to launch meme tokens, trade Solana assets, and claim creator fees on 4chad.xyz. It explicitly implements security best practices by requiring the `SOLANA_PRIVATE_KEY` to be stored locally and used only by a local `sign-transaction.js` script, preventing its transmission over the network. All API interactions are with the stated `https://4chad.xyz` domain, and there is no evidence of data exfiltration to unauthorized endpoints, malicious remote code execution, persistence mechanisms, or prompt injection attempts against the agent to perform actions outside its stated purpose. The use of `curl`, `node`, and `jq` for API interaction and local script execution is aligned with the skill's functionality.
