ton-auditor
Audited by Socket on May 18, 2026
5 alerts found:
Anomalyx2Malwarex3No actual executable code was provided—only an attacker-oriented instruction prompt. There are no discernible runtime capabilities (no inputs handled, no side effects, no source-to-sink paths). As a supply-chain security signal, the presence of explicitly adversarial guidance is a notable integrity red flag, but concrete malware behavior cannot be established from this fragment alone.
This fragment is not executable software or a dependency implementation; it is attacker-oriented instructional content for exploiting TON smart contracts. There are no code-level sources/sinks or concrete malicious execution in the snippet, but the explicit exploitation guidance makes it unsafe as part of a software/agent package because it can enable or automate attack planning when integrated elsewhere.
This fragment represents dangerous operational guidance rather than a safe analysis artifact. It promotes weaponization and cross-contract exploitation practices, which pose substantial risk if followed. Treat as harmful guidance that should be restricted and replaced with a safe, bounded vulnerability disclosure approach.
This fragment is not a software implementation; it is explicitly malicious, attacker-oriented guidance for extracting value from TON smart contracts via economic/value-flow exploitation (Jetton/NFT mechanics, send_mode value draining, bounce persistence, gas/storage exhaustion). Because there is no executable code here, there are no concrete runtime source-to-sink flows to trace, but its presence in a dependency artifact would strongly indicate malicious intent and warrant rejection and deeper repository-level review for hidden/adjacent executable payloads.
No dependency code was provided—only an explicit attacker playbook. There are no executable sources/sinks or concrete exploit paths within this fragment itself. However, the content is directly malicious in intent (access-control exploitation, initialization sabotage, gas-draining tactics, and privilege escalation), making it a high-risk artifact if introduced into a repository or distribution channel. Treat as hostile content; do not import or package it.