constant-time-analysis

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
ct_analyzer/tests/test_samples/decompose_vulnerable.go

No evidence of overt supply-chain malware (no exfiltration/backdoor/system interaction). However, the code is intentionally written to be variable-time: it uses input-derived integer division/modulo and branches on intermediate values (r0, hint). This makes it unsafe for production or any constant-time/side-channel-resistant cryptographic use; its key risk is timing side-channel leakage due to non-constant-time control flow and operations.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
May 6, 2026, 02:11 PM
Package URL
pkg:socket/skills-sh/jswortz%2Fmy-skills%2Fconstant-time-analysis%2F@64f036842c336b2781bda538ae7b8955a25ede38
Security Audit — socket — constant-time-analysis