taiko-shadow

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The artifact documents legitimate but sensitive functionality: creating deterministic L1 deposit addresses, funding them, generating ZK proofs, and claiming on Taiko L2. I found no explicit malicious code patterns in the provided fragment (no hard-coded credentials, no remote malicious domains, no remote-exec). However, the documentation omits critical security controls around secret management, server authentication, and persistence of task metadata. Running the server mode or automated pipelines without those controls materially increases the chance of secret compromise or unauthorized fund transfers. Recommend treating the project as high-risk until secure key-handling and server hardening practices are documented and enforced.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 3, 2026, 11:51 AM
Package URL
pkg:socket/skills-sh/taikoxyz%2Ftaiko-ai%2Ftaiko-shadow%2F@2edfe76446dede10b3e5cad0f861c4f5e15767f4