treasures-b2b-api

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Anomaly
AnomalyLOW
references/trading.md

No clear malware or supply-chain attack is present in this documentation and signing code. The primary security risk is financial and authorization-related: private-key use is shown without storage safeguards, and ERC-20 approvals use maxUint256. Verify token, spender, EIP-712 domain, contract, chain, recipient, amounts, and deadlines before signing or approving, and protect ETH_PRIVATE_KEY. Assessment is limited to this fragment and referenced files are not available.

Confidence: 96%Severity: 57%
Audit Metadata
Analyzed At
Aug 27, 2026, 08:40 AM
Package URL
pkg:socket/skills-sh/treasures-io%2Ftreasures-finance-agent-skills%2Ftreasures-b2b-api%2F@edc5b863e4b0171c00e22d357fca31eec00e9ac4631adf37b2bfbd9ed65477dd
Security Audit — socket — treasures-b2b-api