upscale-image
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomaly.clawnet/unsigned-skill.json
LOWAnomalyLOW
.clawnet/unsigned-skill.json
The package fragment demonstrates a concerning pattern: a large, hex-encoded payload that contains cloud- provisioning instructions and endpoints, paired with provenance data. While not showing direct executable code, the content could influence runtime behavior via a loader that decodes and executes or guides actions based on the payload. This constitutes a non-trivial supply-chain risk and warrants strict validation of decoding, signature verification, and any runtime handling of opReturnHex to prevent credential leakage or unintended cloud resource provisioning.
Confidence: 56%Severity: 65%
Audit Metadata