bitget-wallet

Warn

Audited by Socket on Sep 17, 2026

6 alerts found:

Anomalyx6
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s wallet, swap, signing, and token-analysis capabilities largely match its stated crypto-trading purpose, and the repo appears same-org with Bitget Wallet. However, it enables high-impact financial actions, relies on mutable GitHub-distributed scripts, instructs use of a black-box signer component, and shows an endpoint inconsistency (copenapi vs publicly documented bopenapi) that weakens data-flow trust. No confirmed malware or overt credential exfiltration is evident from the provided content.

Confidence: 84%Severity: 61%
AnomalyLOW
scripts/order_sign.py

The fragment is a wallet transaction-signing utility, not an apparent malware payload. It contains no network exfiltration, shell execution, persistence, or destructive behavior. Its main risk is that externally supplied transaction fields and arbitrary hashes are signed with real private keys, particularly through unsafe_sign_hash and eth_sign, without semantic user confirmation. Review key_utils.read_key_file separately and require strict transaction, chain, recipient, value, and calldata validation before signing.

Confidence: 96%Severity: 68%
AnomalyLOW
scripts/x402_pay.py

The fragment is a cryptocurrency payment and signing utility, not apparent malware. It contains no evident unauthorized exfiltration, backdoor, persistence, destructive action, or obfuscated payload. Its principal security risk is authorization of payments based on untrusted server-supplied metadata: without interactive confirmation, especially with --auto, a malicious endpoint can request payment to an attacker-controlled address up to the hard-coded amount cap. Solana signing also lacks transaction-content and signer-role validation. The code should be used only with trusted endpoints and should validate chain, token, recipient, transaction instructions, and signer status before signing.

Confidence: 97%Severity: 58%
AnomalyLOW
docs/commands.md

This fragment is cryptocurrency wallet-agent documentation with examples for balances, market analysis, swaps, transaction signing, and payments. It exposes high-impact signing capabilities and presents risks around private-key handling, arbitrary x402 URLs, and irreversible transaction execution, but it contains no direct evidence of malware or malicious intent. Assessment is limited because the referenced implementations and call sites are not shown.

Confidence: 93%Severity: 58%
AnomalyLOW
scripts/order_make_sign_send.py

The fragment is a command-line cryptocurrency wallet transaction tool. Its intended behavior is to read private keys, request an order, sign returned transactions, and submit them. No direct malware indicators such as shell execution, persistence, credential exfiltration, suspicious network destinations, or destructive file operations are present in the provided code. The primary security concern is that externally returned transaction data is signed and sent with limited local validation, so compromised API or signing dependencies could cause unauthorized transfers. Review the imported modules and validate transaction contents before signing.

Confidence: 94%Severity: 63%
AnomalyLOW
docs/first-time-setup.md

No malicious behavior is evident because the fragment is non-executable wallet configuration guidance with no exfiltration or backdoor logic. The main security concern is the explicit private-key write to a temporary file, which conflicts with the memory-only key-management rule and should be removed; signing should consume key material directly in memory. Secure-storage and file-permission implementations would require separate review.

Confidence: 98%Severity: 52%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:30 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fbitget-wallet%2F@afeba5bfaa411281af9ba7c01983e32f32557462deb2949a715dbde0bc55d846
Security Audit — socket — bitget-wallet