dapp-connect

Fail

Audited by Socket on May 8, 2026

1 alert found:

Malware
MalwareHIGH
.clawnet/unsigned-skill.json

This fragment is a high-risk supply-chain artifact: it wraps an on-chain OP_RETURN payload that appears intended to be decoded into a wallet-connection UI and to drive sensitive wallet actions (approval/signing/transaction sending). The embedded narrative explicitly signals abusive “drain/bypass safety” intent. Direct proof of execution requires the surrounding decoder/executor, but the payload content itself is strongly consistent with phishing/scam dApp behavior focused on unauthorized or unsafe transaction solicitation.

Confidence: 92%Severity: 80%
Audit Metadata
Analyzed At
May 8, 2026, 05:41 PM
Package URL
pkg:socket/skills-sh/b-open-io%2F1sat-sdk%2Fdapp-connect%2F@a554f1a522dacd106e788ef5993beae3fd3e1b11
Security Audit — socket — dapp-connect