treasures-b2b-api
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
AnomalyAnomalyreferences/trading.md
LOWAnomalyLOW
references/trading.md
No clear malware or supply-chain attack is present in this documentation and signing code. The primary security risk is financial and authorization-related: private-key use is shown without storage safeguards, and ERC-20 approvals use maxUint256. Verify token, spender, EIP-712 domain, contract, chain, recipient, amounts, and deadlines before signing or approving, and protect ETH_PRIVATE_KEY. Assessment is limited to this fragment and referenced files are not available.
Confidence: 96%Severity: 57%
Audit Metadata