debridge

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/external-calls/README.md

No direct evidence of supply-chain malware is present in the visible fragment (no secrets, no obfuscation, no stealthy execution, no exfiltration). However, the fragment is a high-privilege transaction-construction helper that accepts arbitrary destination contract address and raw external-call calldata, then submits a transaction that will drive cross-chain external execution. This is primarily a misuse/capability risk: integrating applications must strictly validate/whitelist targetContract and externalCallData (and understand fallback behavior) and rely on the on-chain program to enforce constraints. Review the on-chain program and the omitted helper functions to confirm that call-data/account inputs are bounded and authorized.

Confidence: 56%Severity: 52%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:08 PM
Package URL
pkg:socket/skills-sh/sendaifun%2Fskills%2Fdebridge%2F@75f04ec2b3a2d7616eb9846472f08f9fefeb2a66e928792eff6d94e0f66337b7
Security Audit — socket — debridge