timelock

Fail

Audited by Socket on May 8, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and uses proportionate dependencies for BSV timelock operations, with no clear credential harvesting or stealth behavior. Its main risk is that it equips an AI agent to perform cryptocurrency transactions, so it is best classified as suspicious/high-risk functionality rather than malware.

Confidence: 90%Severity: 72%
MalwareHIGH
.clawnet/unsigned-skill.json

This artifact is a packaged OP_RETURN data payload with provenance metadata that, when decoded/parsed by downstream systems, appears to carry harmful/coercive “lock/unlock” and abuse-oriented directives, including references consistent with external tracking/telemetry. Although this fragment contains no executable code or direct network/file operations, its design strongly suggests it is meant to be trusted and acted on by other tooling—making it a high supply-chain risk until downstream parsing/execution and the referenced documentation are verified.

Confidence: 72%Severity: 78%
Audit Metadata
Analyzed At
May 8, 2026, 05:42 PM
Package URL
pkg:socket/skills-sh/b-open-io%2F1sat-sdk%2Ftimelock%2F@31a94ab81445c79c6dfe92bda7aaa21807789850
Security Audit — socket — timelock