1sat-stack

Fail

Audited by Socket on May 8, 2026

1 alert found:

Malware
MalwareHIGH
.clawnet/unsigned-skill.json

This fragment strongly indicates malicious or highly deceptive supply-chain content: it embeds an obfuscated instruction set (OP_RETURN-like hex plus signer metadata) describing automated blockchain wallet/UTXO/token discovery and subsequent spend/transfer/submit/broadcast transaction actions via HTTP API endpoints, along with monitoring/streaming. Even without the surrounding decoder/executor code, the embedded side-effect workflow and deceptive language make the module extremely high risk and unsuitable for production use until the referenced implementation files are inspected, deobfuscated, and verified to be non-actionable and non-stealing/non-authorizing.

Confidence: 90%Severity: 85%
Audit Metadata
Analyzed At
May 8, 2026, 05:41 PM
Package URL
pkg:socket/skills-sh/b-open-io%2F1sat-sdk%2F1sat-stack%2F@bd50261523298553bd6971f34effa67b2abf4e45
Security Audit — socket — 1sat-stack