Sato Hub
← Sato Check

Sato Check · Package

@raydium-io/raydium-sdk-v2

npm:@raydium-io/raydium-sdk-v2 · as of 2026-09-26

Does it take your key?
declared
It asks for a private key or seed phrase in its setup.
The project says so — README, config, env list or tool description.
Does your key leave?
observed
Not observed — no planted key left during install and start-up, under our test conditions — code paths that only run later, or only on a trigger, are not covered.
We ran it with planted test keys and saw it.
Can it move funds on its own?
no evidence
Unknown — we could not read what it exposes.
No evidence line on file for this question yet.
What changed?
observed
No change in key, host or fund behaviour since the previous version.
We ran it with planted test keys and saw it.

Is this your project? Respond →Dispute this reading

Hosts contacted

HostWhenRoleEvidence
registry.npmjs.orginstallregistryobserved
nodejs.orginstallotherobserved
Evidence (3 lines)
  • observedO-hosts2026-09-25

    registry.npmjs.org was contacted during install (registry).

    sandbox:obs_8bb06a7872d66e1f

  • observedO-hosts2026-09-25

    nodejs.org was contacted during install (other).

    sandbox:obs_8bb06a7872d66e1f

  • declaredD-env-key2026-09-26

    Setup names A Solana keypair/wallet (owner) + RPC connection; funded SOL as something to provide.

    deploy_spec.requires

Limits

  • The traced lane has not run on this version: tarball is 31162939 bytes, over the 15728640-byte cap
  • Traced analysis follows flows inside one module only; a key handed from one module to another is not followed.
  • Traced lane did not run: tarball is 31162939 bytes, over the 15728640-byte cap.
  • Key egress not observed during install and start-up, under our test conditions — code paths that only run later, or only on a trigger, are not covered.
  • No tool inventory was available, so fund actions were not read.
  • Sandbox: DNS queries made directly by the target are not logged; hosts are recorded from proxied HTTP(S) requests and CONNECTs..
  • Sandbox: Code that ignores HTTP(S)_PROXY has no route out of the sandbox, so its attempts are not captured..

A profile describes what we read and ran, with dates. It is not a safety rating, an audit or an endorsement, and "not found" is not "not there".

sato.custody/v1 · custody-1

Maintain this project? Respond to this reading

Loading sign-in…