erc-8004
Audited by Socket on Sep 24, 2026
4 alerts found:
Anomalyx2Securityx2SUSPICIOUS. The skill’s capabilities broadly fit its purpose, but it enables autonomous financial/on-chain actions and depends on opaque local shell scripts not included in the review. Credential use is mostly proportionate, yet the bridge and registration execution paths are not transparent enough to call benign.
The intended function is an agent profile update, but direct interpolation of command-line input into node -e creates a command-injection vulnerability capable of arbitrary local JavaScript execution when a crafted argument is supplied. User-provided transaction data is also sent through Bankr, so review and confirmation behavior depends on that CLI. No clear evidence of intentional malware is present.
The script implements an agent-registration workflow and shows no clear intentional malware. However, unescaped IPFS_URI interpolation into node -e can permit local code execution if the helper output is attacker-controlled. Mainnet transaction submission is also the default, and output JSON is not safely escaped. Review the helper scripts and validate the URI before use.
The script has a significant code-injection vulnerability: a crafted REGISTRATION_URL can execute arbitrary JavaScript through node -e. It also submits a transaction through Bankr as intended. No clear evidence of deliberate malware is present, but the injection risk makes the script unsafe with untrusted URL values.