sweep-import

Fail

Audited by Socket on May 8, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and not overtly malicious, but it is intrinsically high risk because it handles raw private keys and authorizes irreversible crypto asset transfers. Treat as suspicious/high-risk operationally due to financial-action capability, not because of clear exfiltration or deceptive install behavior.

Confidence: 78%Severity: 72%
MalwareHIGH
.clawnet/unsigned-skill.json

This artifact is highly suspicious and strongly consistent with a malicious supply-chain component designed for cryptocurrency wallet/token draining. The embedded payload explicitly references importing/controlling private keys/WIF, fetching remote data to select spendable outputs, and constructing/executing token transfer (“sweep”) operations—typical of theft automation. While the exact executable code is not provided, the encoded operational instructions themselves indicate malicious intent. Treat as unsafe and do not install/use without thorough isolated analysis and remediation.

Confidence: 98%Severity: 92%
Audit Metadata
Analyzed At
May 8, 2026, 05:43 PM
Package URL
pkg:socket/skills-sh/b-open-io%2F1sat-sdk%2Fsweep-import%2F@f31bee12f64bd0a8177670c1bbee24021e20be52
Security Audit — socket — sweep-import