debridge

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/external-calls/README.md

No direct evidence of supply-chain malware is present in the visible fragment (no secrets, no obfuscation, no stealthy execution, no exfiltration). However, the fragment is a high-privilege transaction-construction helper that accepts arbitrary destination contract address and raw external-call calldata, then submits a transaction that will drive cross-chain external execution. This is primarily a misuse/capability risk: integrating applications must strictly validate/whitelist targetContract and externalCallData (and understand fallback behavior) and rely on the on-chain program to enforce constraints. Review the on-chain program and the omitted helper functions to confirm that call-data/account inputs are bounded and authorized.

Confidence: 56%Severity: 52%
Audit Metadata
Analyzed At
Aug 4, 2026, 12:33 AM
Package URL
pkg:socket/skills-sh/JustaName-id%2Fcryptoskills%2Fdebridge%2F@f61af4f29977ba70986987b9140e522e5165e9c2039e930da7b66ec7307dcb43
Security Audit — socket — debridge