message-signing
Warn
Audited by Gen Agent Trust Hub on Mar 24, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: Multiple example scripts contain hardcoded Bitcoin private keys in WIF format (e.g.,
KzmFJcMXHufPNHixgHNwXBt3mHpErEUG6WFbmuQdy525DezYAi82) used for demonstration purposes inexamples/brc77-private-sig.ts,examples/bsm-sign-verify.ts, andexamples/sigma-multi-sig.ts. - [DATA_EXFILTRATION]: The
remoteSignfunctionality documented inreferences/sigma-advanced.mdfacilitates the transmission of authentication headers and API keys to external URLs via HTTP POST requests. - [COMMAND_EXECUTION]: The documentation instructs users to execute package installation commands (
bun add sigma-protocol,npm install -g bsv-bap) for external libraries.
Audit Metadata