thor

Fail

Audited by Socket on Mar 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/built-in-contracts.md

No explicit malicious code is visible in this specification text. However, built-in native contracts are consensus- and value-critical components implemented in Go outside the EVM, making them high-sensitivity infrastructure. Primary security risks identified: centralized executor privilege enabling arbitrary calls and Params modifications; potential for economic manipulation via Energy/Rewards and Staker/Delegation state changes; complex cross-contract and transition-period logic that increases the chance of subtle bugs; and the elevated blast radius of any bug or malicious change in native Go handlers. Recommended actions: perform a full code audit of the Go native implementations (search for network I/O, hard-coded credentials, privileged backdoors, incorrect auth checks), review governance processes protecting Executor actions, add regression tests for transition logic and gas/revert semantics across contract versions, and apply code review & signed releases for native binaries.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 17, 2026, 12:59 PM
Package URL
pkg:socket/skills-sh/vechain%2Fvechain-ai-skills%2Fthor%2F@89c481de5e555b005d8f01822d138325b64c7303