signals

Warn

Audited by Socket on Sep 24, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS: The core blockchain-signing and signal-publication capabilities fit the stated purpose, and there is no evidence of a malicious installer or hidden payload. Risk comes from credential forwarding to Bankr, remote heartbeat-driven behavior, and legacy API examples that reduce trust and increase the chance of unsafe autonomous actions.

Confidence: 88%Severity: 64%
SecurityMEDIUM
scripts/publish-signal.sh

The script has a significant command-line-to-JavaScript injection vulnerability in the node -e message construction. Crafted ACTION or TOKEN input can execute JavaScript in a process containing PRIVATE_KEY. The key is not directly sent by the normal code path, and malicious intent is not established, but this should be fixed by passing values as safely encoded data rather than interpolating them into source. Use a trusted API endpoint.

Confidence: 98%Severity: 76%
Audit Metadata
Analyzed At
Sep 24, 2026, 04:46 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fskills%2Fsignals%2F@d50e8bc4daa4cda7da14d8ebc999af237b766cf28b812c02f71ddd4ef9d94ada
Security Audit — socket — signals