ordinals-create

Warn

Audited by Socket on Aug 25, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/mint.ts

No clear evidence of stealthy malware or obfuscation exists in this module; the logic is straightforward CLI-based file read, optional metadata parsing, base64 encoding, and remote inscription submission. However, the module has notable security/trust risks: it accepts a raw WIF private key from command-line arguments and supplies it to a hardcoded remote wallet endpoint, meaning key material is dependent on third-party handling; additionally, it can read and upload any user-specified local file without size/path controls. Overall, the main risk is credential-handling and supply-chain/remote-trust impact rather than malicious payload behavior in this snippet.

Confidence: 66%Severity: 58%
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior matches the stated purpose of minting BSV ordinals, and the referenced tooling appears consistent with the 1Sat ecosystem, so this is not fundamentally deceptive. The main risks are proportionate but significant: it forwards a wallet WIF into code/dependencies, enables irreversible fund-spending/public blockchain actions, and expands trust by invoking another skill.

Confidence: 85%Severity: 67%
Audit Metadata
Analyzed At
Aug 25, 2026, 03:12 PM
Package URL
pkg:socket/skills-sh/b-open-io%2F1sat-sdk%2Fordinals-create%2F@b0d6eaf94f2f33969b3739502e688abcacaf48ada8e190a44a4e623911c881a3