mev-protection

Warn

Audited by Socket on Aug 3, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/flashbots_relay.py

No direct malicious/backdoor behavior is evident in this module (no covert exfiltration, no obfuscation, no persistence, no dynamic execution). However, it is a high-privilege component: it signs and submits externally-specified transactions/bundles using a PRIVATE_KEY from the environment, meaning untrusted stdin can drive on-chain execution with spend capability from that key. This makes the primary risk operational/misuse-driven rather than malware-driven; integration controls (input validation, allowlists, least-privilege key management, and explicit user consent/confirmation) are essential.

Confidence: 68%Severity: 60%
Audit Metadata
Analyzed At
Aug 3, 2026, 07:55 PM
Package URL
pkg:socket/skills-sh/XSpoonAi%2Fspoon-awesome-skill%2Fmev-protection%2F@109f546ad5d02404feb076d636fb2954ad0860d6c47b0aa8c930a75900aa2cda
Security Audit — socket — mev-protection