Agent skill

Pump Security

by nirholas in nirholas/pump-fun-sdk

Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege management, dependency…

Custom licenceAuto-check passedSecurity

Install Pump Security

skills CLI
$ npx skills add nirholas/pump-fun-sdk --skill pump-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nirholas/pump-fun-sdk pump-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nirholas/pump-fun-sdk.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pump-security .claude/skills/pump-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pump-security
GitHub stars
133
Token cost
~892 tokens
SKILL.md length
349 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
Custom licence

At a glance

Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege management, dependency…

  • Works in 5 steps: Re-derive public key from secret key → Compare derived key with stored public key → Sign a test message with the keypair → …
  • Tasks that involve Cryptography
  • SKILL.md covers Memory Zeroization, RNG Quality, Keypair Integrity Verification and Secure File I/O, plus 5 more sections
  • Calls cargo and npm

What it does

Pump Security is an agent skill from nirholas/pump-fun-sdk. Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege management, dependency auditing, and a 60+ item security checklist.

Its SKILL.md is about 890 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cryptography, Secure coding and Security review. It works with Rust, TypeScript, Bash and Solana. The repository describes itself as: Token creation launching, bonding curve trading, AMM migration, tiered fees, creator fee sharing, vanity keygen, MCP server, Telegram bot & live dashboards.

When your agent uses it

  • Tasks that involve Cryptography
  • Tasks that involve Secure coding
  • Tasks that involve Security review

Example prompts

  • “/pump-security”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Re-derive public key from secret key
  2. Compare derived key with stored public key
  3. Sign a test message with the keypair
  4. Verify the signature with the public key
  5. Validate Base58 encoding roundtrip

What it can do on your machine

Read from SKILL.md and the folder at commit fcfc876. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pump Security loads about 892 tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 349 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~892

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 349 words (~892 tokens).

“Defense-in-depth security across Rust, TypeScript, and Bash: key handling, memory zeroization, secure file I/O, input validation, privilege management, and dependency auditing.”

— opening of SKILL.md by nirholas, Custom licence
name
pump-security

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/pump-security of nirholas/pump-fun-sdk.

Open the folder on GitHubat commit fcfc876

Compare with similar skills

Pump Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pump Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pump Security this skillnirholas/pump-fun-sdk133—~892Automated safety check: PassCustom licence
Zeroization Audittrailofbits/skills7.4k4 repos~5.9kAutomated safety check: NotesCC-BY-SA-4.0
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Security Reviewdeadlock-mod-manager/deadlock-mod-manager473—~1.8kAutomated safety check: PassCC-BY-SA-4.0
Sharp Edges Analysistrailofbits/skills7.4k3 repos~3kAutomated safety check: PassCC-BY-SA-4.0

Similar skills

  • Zeroization Audit

    trailofbits/skills

    Official

    Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis.

    7.4k GitHub starsUsed in 4 repos~5.9k tokens
    SecurityAuto-check: notes
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Security Review

    deadlock-mod-manager/deadlock-mod-manager

    Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

    473 GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Sharp Edges Analysis

    trailofbits/skills

    Official

    Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis.

    7.4k GitHub starsUsed in 3 repos~3k tokens
    SecurityAuto-check passed
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from nirholas/pump-fun-sdk

All 18 skills in this repo
  • Pump AI Agents

    nirholas/pump-fun-sdk

    AI agent integration layer for the Pump SDK — agent instruction files, .well-known discovery, LLM context documents, 15+ skill files, MCP server prompts, and terminal management rules for GitHub…

    133 GitHub starsUsed in 1 repo~832 tokens
    Auto-check passed
  • Pump Admin Ops

    nirholas/pump-fun-sdk

    Admin and authority operations for the Pump protocol — set coin creator, update token incentives, set IDL authority, claim cashback, Mayhem mode, and BothPrograms cross-program admin instructions.

    133 GitHub stars~684 tokensUpdated 18 days ago
    Auto-check passed
  • Pump Bonding Curve

    nirholas/pump-fun-sdk

    Constant-product AMM bonding curve math for Pump token pricing — buy/sell quoting, fee-aware calculations, market cap computation, tiered fees, ceiling division, virtual vs real reserves, and…

    133 GitHub stars~1.2k tokensUpdated 18 days ago
    Auto-check passed
  • Pump Build Release

    nirholas/pump-fun-sdk

    Build and release pipeline for the Pump SDK — tsup TypeScript builds, Cargo release profiles, semantic release with commitizen, npm publishing, linting, Makefile targets, Vercel deployment, and MCP…

    133 GitHub stars~620 tokensUpdated 18 days ago
    Auto-check passed
  • Pump Claims Readonly

    nirholas/pump-fun-sdk

    Read-only query methods for PumpFun claims — unclaimed token rewards, creator vault balances, volume accumulators, distributable fees, and current-day token previews across Pump and PumpAMM programs.

    133 GitHub stars~2.1k tokensUpdated 18 days ago
    Auto-check passed
  • Pump Fee Sharing

    nirholas/pump-fun-sdk

    Configure and distribute creator fees to multiple shareholders using the PumpFees program with BPS-based share allocation, admin management, and cross-program fee consolidation for graduated tokens.

    133 GitHub stars~841 tokensUpdated 18 days ago
    Auto-check passed

Categories

Questions about Pump Security

What does Pump Security do?

Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege management, dependency…. Pump Security is an agent skill from nirholas/pump-fun-sdk. Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege management, dependency auditing, and a 60+ item security checklist.

When should I use Pump Security?

Pump Security fits situations like: tasks that involve Cryptography; tasks that involve Secure coding; tasks that involve Security review.

How do I install Pump Security in Claude Code?

Run `npx skills add nirholas/pump-fun-sdk --skill pump-security -a claude-code`. Or copy the skill folder (skills/pump-security in nirholas/pump-fun-sdk) into .claude/skills/pump-security in your project. Claude Code loads it when a task matches its description.

How do I install Pump Security in Codex?

Run `npx skills add nirholas/pump-fun-sdk --skill pump-security -a codex`. Or copy the skill folder (skills/pump-security in nirholas/pump-fun-sdk) into .agents/skills/pump-security in your project. Codex loads it when a task matches its description.

Can I use Pump Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nirholas/pump-fun-sdk --skill pump-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pump-security, .gemini/skills/pump-security, .github/skills/pump-security and .opencode/skills/pump-security in your project.

What does Pump Security need to run?

Going by SKILL.md and its folder, Pump Security needs the command-line tools its instructions call (cargo and npm). Our summary lists: Node.js.

Does Pump Security access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Pump Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pump Security use?

Pump Security has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Pump Security use?

About 892 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pump Security?

Skills that share tags, products or a category with Pump Security: Zeroization Audit (trailofbits/skills, 7.4k stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars) and Security Review (deadlock-mod-manager/deadlock-mod-manager, 473 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pump Security?

nirholas (a GitHub user) maintains it in nirholas/pump-fun-sdk, which has 133 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on September 18, 2026.

Source: nirholas/pump-fun-sdk on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.