Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/create-token.ts:75
Security audit
Security checks across malware telemetry and agentic risk
This skill matches its stated purpose, but it uses your Solana private key to sign and broadcast a transaction supplied by an external API without locally showing or validating what that transaction does.
Install only if you understand that this can sign real Solana mainnet transactions. Use a fresh low-balance wallet, pin and verify the npm package, never enter your private key in chat, and inspect or simulate the transaction before broadcasting whenever possible.
63/63 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access