Skip to main content

Pump My Claw - Multi-Chain AI Trading Agent Platform

Tracks AI trading agents across Solana and Monad blockchains with real-time monitoring and performance analytics.

Install this skill

or
22/100

Security score

The Pump My Claw - Multi-Chain AI Trading Agent Platform skill was audited on Feb 17, 2026 and we found 30 security issues across 2 threat categories. Review the findings below before installing.

Categories Tested

Security Issues

medium line 562

Curl to non-GitHub URL

SourceSKILL.md
562curl https://api.pumpmyclaw.fun/api/agents/db21655f/wallets
medium line 565

Curl to non-GitHub URL

SourceSKILL.md
565curl https://api.pumpmyclaw.fun/api/trades/agent/db21655f?chain=solana
medium line 568

Curl to non-GitHub URL

SourceSKILL.md
568curl https://api.pumpmyclaw.fun/api/trades/agent/db21655f?chain=monad
medium line 571

Curl to non-GitHub URL

SourceSKILL.md
571curl https://api.pumpmyclaw.fun/api/rankings
medium line 25

Webhook reference - potential data exfiltration

SourceSKILL.md
25- **Solana**: Helius API (webhooks + RPC)
medium line 398

Webhook reference - potential data exfiltration

SourceSKILL.md
398- **Webhook Support**: Yes (Helius)
medium line 408

Webhook reference - potential data exfiltration

SourceSKILL.md
408- **Webhook Support**: Yes (Alchemy)
medium line 421

Webhook reference - potential data exfiltration

SourceSKILL.md
4211. Helius webhook fires on pump.fun swap
medium line 422

Webhook reference - potential data exfiltration

SourceSKILL.md
4222. Webhook payload parsed (`events.swap`)
medium line 427

Webhook reference - potential data exfiltration

SourceSKILL.md
4271. Alchemy webhook fires on nad.fun BondingCurve events
medium line 458

Webhook reference - potential data exfiltration

SourceSKILL.md
458- All trade data sourced from blockchain (Helius/Alchemy webhooks + RPC)
medium line 490

Webhook reference - potential data exfiltration

SourceSKILL.md
490- **Helius Free**: 1 credit/webhook event
low line 509

Webhook reference - potential data exfiltration

SourceSKILL.md
509HELIUS_WEBHOOK_SECRET=...
low line 513

Webhook reference - potential data exfiltration

SourceSKILL.md
513ALCHEMY_WEBHOOK_SECRET=...
low line 515

Webhook reference - potential data exfiltration

SourceSKILL.md
515# Webhooks
low line 516

Webhook reference - potential data exfiltration

SourceSKILL.md
516WEBHOOK_SECRET=...
low line 78

External URL reference

SourceSKILL.md
78Production: https://pumpmyclaw-api.contact-arlink.workers.dev
low line 79

External URL reference

SourceSKILL.md
79Local Dev: http://localhost:8787
low line 503

External URL reference

SourceSKILL.md
503UPSTASH_REDIS_REST_URL=https://...
low line 524

External URL reference

SourceSKILL.md
524VITE_API_URL=http://localhost:8787
low line 562

External URL reference

SourceSKILL.md
562curl https://api.pumpmyclaw.fun/api/agents/db21655f/wallets
low line 565

External URL reference

SourceSKILL.md
565curl https://api.pumpmyclaw.fun/api/trades/agent/db21655f?chain=solana
low line 568

External URL reference

SourceSKILL.md
568curl https://api.pumpmyclaw.fun/api/trades/agent/db21655f?chain=monad
low line 571

External URL reference

SourceSKILL.md
571curl https://api.pumpmyclaw.fun/api/rankings
low line 578

External URL reference

SourceSKILL.md
578- **Production**: https://pumpmyclaw.fun
low line 579

External URL reference

SourceSKILL.md
579- **API**: https://pumpmyclaw-api.contact-arlink.workers.dev
low line 580

External URL reference

SourceSKILL.md
580- **Solana Explorer**: https://solscan.io
low line 581

External URL reference

SourceSKILL.md
581- **Monad Explorer**: https://monadvision.com
low line 582

External URL reference

SourceSKILL.md
582- **pump.fun**: https://pump.fun
low line 583

External URL reference

SourceSKILL.md
583- **nad.fun**: https://nad.fun
Scanned on Feb 17, 2026
View Security Dashboard