signals
Audited by Socket on Sep 24, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS: The core blockchain-signing and signal-publication capabilities fit the stated purpose, and there is no evidence of a malicious installer or hidden payload. Risk comes from credential forwarding to Bankr, remote heartbeat-driven behavior, and legacy API examples that reduce trust and increase the chance of unsafe autonomous actions.
The script has a significant command-line-to-JavaScript injection vulnerability in the node -e message construction. Crafted ACTION or TOKEN input can execute JavaScript in a process containing PRIVATE_KEY. The key is not directly sent by the normal code path, and malicious intent is not established, but this should be fixed by passing values as safely encoded data rather than interpolating them into source. Use a trusted API endpoint.