erc-8004

Warn

Audited by Socket on Sep 24, 2026

4 alerts found:

Anomalyx2Securityx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly fit its purpose, but it enables autonomous financial/on-chain actions and depends on opaque local shell scripts not included in the review. Credential use is mostly proportionate, yet the bridge and registration execution paths are not transparent enough to call benign.

Confidence: 87%Severity: 66%
SecurityMEDIUM
scripts/update-profile.sh

The intended function is an agent profile update, but direct interpolation of command-line input into node -e creates a command-injection vulnerability capable of arbitrary local JavaScript execution when a crafted argument is supplied. User-provided transaction data is also sent through Bankr, so review and confirmation behavior depends on that CLI. No clear evidence of intentional malware is present.

Confidence: 99%Severity: 78%
AnomalyLOW
scripts/register.sh

The script implements an agent-registration workflow and shows no clear intentional malware. However, unescaped IPFS_URI interpolation into node -e can permit local code execution if the helper output is attacker-controlled. Mainnet transaction submission is also the default, and output JSON is not safely escaped. Review the helper scripts and validate the URI before use.

Confidence: 96%Severity: 68%
SecurityMEDIUM
scripts/register-http.sh

The script has a significant code-injection vulnerability: a crafted REGISTRATION_URL can execute arbitrary JavaScript through node -e. It also submits a transaction through Bankr as intended. No clear evidence of deliberate malware is present, but the injection risk makes the script unsafe with untrusted URL values.

Confidence: 99%Severity: 82%
Audit Metadata
Analyzed At
Sep 24, 2026, 04:46 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fskills%2Ferc-8004%2F@7bc349180ba6b0e174028c1488f4cfb517777d29b88a1d5f5a930f387ea828a7
Security Audit — socket — erc-8004