blockchain-security

Warn

Audited by Socket on May 11, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
reference/delegatecall-attacks.md

No direct supply-chain malware behavior (exfiltration, persistence, credential theft, or network beacons) is evidenced in the provided fragment because it reads as an educational attack description rather than runtime library code. However, it describes a severely dangerous contract vulnerability pattern: attacker-controlled `delegatecall` with storage-layout mirroring, enabling unauthorized state changes in the victim contract’s storage. If similar logic exists in a real dependency/module, it would be a significant security alert requiring immediate review and mitigation (restrict delegatecall targets, enforce allowlists, and avoid arbitrary delegatecall).

Confidence: 70%Severity: 65%
SecurityMEDIUM
SKILL.md

The skill is internally coherent for blockchain exploitation and CTF use, but it is high risk because it gives an AI agent offensive security capabilities plus the ability to sign and broadcast blockchain transactions. Tooling sources appear mostly legitimate, so the main concern is autonomous exploit execution, not hidden malware or credential exfiltration.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
May 11, 2026, 07:48 AM
Package URL
pkg:socket/skills-sh/transilienceai%2Fcommunitytools%2Fblockchain-security%2F@d3d363797ecf2fe4b0ec6ccfa7dc0c4e3e8253be
Security Audit — socket — blockchain-security