Back to skill

Security audit

Pump Fun

Security checks across malware telemetry and agentic risk

Overview

This skill is clearly for Pump.fun crypto trading, but it asks for wallet authority and describes real fund-moving actions without enough visible implementation or transaction safeguards.

Review carefully before installing. Use only a dedicated low-balance wallet, never a main wallet, and do not set SOLANA_PRIVATE_KEY unless you can inspect and trust the actual implementation that will submit transactions. Manually verify mint addresses, amounts, slippage, fees, and wallet impact before any buy, sell, or token launch.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill exposes commands that can buy, sell, and launch tokens on-chain using a configured private key, but the command descriptions do not prominently warn that these actions are irreversible and can directly spend user funds. In a high-risk trading context involving memecoins and token launches, omission of an explicit transactional risk warning increases the chance of accidental loss, especially for users invoking commands conversationally.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.