extract-blockchain-media

Fail

Audited by Socket on May 8, 2026

1 alert found:

Malware
MalwareHIGH
.clawnet/unsigned-skill.json

High-risk: the embedded signed OP_RETURN payload appears to function as an instruction carrier for an automated workflow that downloads media from specified HTTPS endpoints, writes extracted content to disk, embeds it into formatted output (HTML/media tags), and invokes a local extraction script/workflow. Even without the implementation of scripts/extract.ts and the OP_RETURN interpreter, the combination of network+filesystem+local execution directives within an obfuscated on-chain payload is strongly consistent with malicious orchestration or sabotage. Recommend quarantining and performing full code review of the OP_RETURN decoding/parsing and the scripts/extract.ts execution path, including verification of all network destinations, file-writing locations, and any process-spawn behavior.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
May 8, 2026, 05:41 PM
Package URL
pkg:socket/skills-sh/b-open-io%2F1sat-sdk%2Fextract-blockchain-media%2F@bde36b9f8b62a723be7dd0b0a85a04029008fe8f
Security Audit — socket — extract-blockchain-media