ens-primary-name

Warn

Audited by Socket on Sep 24, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
scripts/set-primary.sh

The script has a significant local JavaScript injection vulnerability: a crafted command-line ENS_NAME can escape the string literal passed to node -e and execute arbitrary code as the invoking user. Input is also inserted into a GraphQL/JSON request without escaping. The visible transaction behavior is consistent with setting an ENS reverse record; there is no clear evidence of intentional malware.

Confidence: 99%Severity: 78%
SecurityMEDIUM
scripts/set-avatar.sh

The script has a significant JavaScript injection vulnerability: crafted ENS_NAME or AVATAR_URL arguments can execute arbitrary code through node -e. It also constructs an unescaped GraphQL query and submits a wallet-authorized transaction. No explicit malware behavior is evident, but the script should not be used with untrusted arguments; pass values safely to Node rather than interpolating them into source code.

Confidence: 99%Severity: 83%
Audit Metadata
Analyzed At
Sep 24, 2026, 04:46 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fskills%2Fens-primary-name%2F@b9805ac2ab6248d775ab0cb13c0c09920cda2db0c47b0c4d78a867f49ee9753c
Security Audit — socket — ens-primary-name