key-derivation

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
.clawnet/unsigned-skill.json

The fragment itself does not contain executable malware, but the opaque opReturnHex payload, combined with hardcoded signer artifacts and cryptography-focused references, represents medium to moderate risk. Downstream components that decode and act on opReturnHex could inadvertently derive keys or exfiltrate sensitive material if provenance, decoding safeguards, and trust anchors are not properly enforced. Recommend restricting decoding to a controlled, verifiable environment and validating provenance of all cryptographic artifacts before integration.

Confidence: 65%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:06 PM
Package URL
pkg:socket/skills-sh/b-open-io%2Fbsv-skills%2Fkey-derivation%2F@2968563fcc7742e80b2f60f74dacb4e6e3b6803a