tenderly

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/web3-action/README.md

No overt supply-chain malware indicators are present in this fragment (no obfuscation, dynamic execution, filesystem/process access, or credential harvesting). The main risk is security design: the webhook-triggered action uses an operator private key to execute privileged `pause()`/`unpause()` transactions on a contract address supplied by an untrusted webhook payload, with only minimal validation and no shown authentication/authorization or contract allowlist enforcement. This makes the module potentially dangerous if the webhook endpoint is reachable or insufficiently protected; the Slack/RPC egress paths are consistent with intended monitoring/reporting but would also amplify impact if secrets are compromised.

Confidence: 66%Severity: 62%
Audit Metadata
Analyzed At
Aug 4, 2026, 12:35 AM
Package URL
pkg:socket/skills-sh/JustaName-id%2Fcryptoskills%2Ftenderly%2F@d168a7d51efa6bc138828f58b188c31686486164ce12712f7d526ee8f8279cc1
Security Audit — socket — tenderly