github-vesting

Warn

Audited by Socket on Jul 5, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md
AnomalyLOW
references/ONE-LINE-INTENTS.md

No direct, embedded malicious code is present in the provided fragment (it is a plain-text workflow/spec). The primary security concern is operational: the workflow orchestrates wallet signing and on-chain transaction submission via external endpoints, which—if validation or allowlisting is flawed—could enable unauthorized contract calls. Since the actual implementation and the critical referenced validation/schema files are not included, malware confidence is low, but overall security risk is medium due to high-impact side effects and missing enforceable code in this snippet.

Confidence: 55%Severity: 60%
Audit Metadata
Analyzed At
Jul 5, 2026, 02:11 PM
Package URL
pkg:socket/skills-sh/BankrBot%2Fopenclaw-skills%2Fgithub-vesting%2F@e98392029d68996e1b098815ce935f15ae2391eca522e6c316fe33bbbdbe8768
Security Audit — socket — github-vesting