mesh-wallet

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
PATTERNS.md

The fragment does not indicate malicious supply-chain behavior. It documents legitimate Cardano wallet signing and transaction submission APIs. The main security concerns are unsafe example deployment patterns: an unauthenticated Express endpoint can cause a server-held wallet to sign arbitrary recipient and amount values, and verifySignature does not actually compare the signing address with expectedAddress. These are significant application-level risks requiring authentication, authorization, validation, transaction limits, and proper address binding, but they are not evidence of malware in the library.

Confidence: 97%Severity: 67%
Audit Metadata
Analyzed At
Sep 20, 2026, 03:10 PM
Package URL
pkg:socket/skills-sh/meshjs%2Fskills%2Fmesh-wallet%2F@c2fc005c010efb4aaa958b5430398271330d8ef636d1f0747be58d72d1369e9f
Security Audit — socket — mesh-wallet