message-signing

Warn

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: Multiple example scripts contain hardcoded Bitcoin private keys in WIF format (e.g., KzmFJcMXHufPNHixgHNwXBt3mHpErEUG6WFbmuQdy525DezYAi82) used for demonstration purposes in examples/brc77-private-sig.ts, examples/bsm-sign-verify.ts, and examples/sigma-multi-sig.ts.
  • [DATA_EXFILTRATION]: The remoteSign functionality documented in references/sigma-advanced.md facilitates the transmission of authentication headers and API keys to external URLs via HTTP POST requests.
  • [COMMAND_EXECUTION]: The documentation instructs users to execute package installation commands (bun add sigma-protocol, npm install -g bsv-bap) for external libraries.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 24, 2026, 11:02 PM