erc-8004

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/register-http.sh

The script's intended function is benign (on-chain registration of a URL), but it contains a high-risk code-injection vulnerability: embedding REGISTRATION_URL into an inline node -e single-quoted string allows arbitrary JavaScript execution if the URL contains a single-quote or crafted payload. The script also trusts a local helper (~/thinkfleet/.../bankr.sh) without integrity checks, which expands the attack surface for credential theft or arbitrary command execution. No explicit hard-coded secrets or obvious backdoor code are present in the file itself, but the injection and trust of a user-writable helper constitute a meaningful security risk that should be remediated before use.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:15 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Ferc-8004%2F@98375e872aa0bd51704914912914e7766561692f