transaction-building

Fail

Audited by Socket on May 8, 2026

2 alerts found:

AnomalyMalware
AnomalyLOW
SKILL.md

BENIGN for purpose alignment and install trust: it is a documentation-style skill for BSV transaction construction using npm packages and coherent blockchain workflows. However, it carries HIGH operational risk because it enables an AI agent to perform cryptocurrency signing and payment actions with real-world financial consequences.

Confidence: 87%Severity: 68%
MalwareHIGH
.clawnet/unsigned-skill.json

This fragment is not benign configuration. It is a highly suspicious OP_RETURN-style payload container that embeds explicit transaction/signing/script-execution workflow instructions and includes metadata intended to authorize acceptance by a downstream consumer. If any part of the package decodes and applies these instructions automatically, it could enable unauthorized value movement or attacker-controlled script behavior. Treat as a potential malicious supply-chain payload pending verification of how/where opReturnHex and the signature metadata are decoded and executed.

Confidence: 80%Severity: 80%
Audit Metadata
Analyzed At
May 8, 2026, 05:41 PM
Package URL
pkg:socket/skills-sh/b-open-io%2F1sat-sdk%2Ftransaction-building%2F@711e678d0a0c42f361208e0130ef186ad1dd9ad0
Security Audit — socket — transaction-building