ton-bug-triage

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
references/probing_patterns.md

This document is an explicit developer blueprint for injecting protocol-level mutations (withholding, malformed packets, reordering, delays, invalid artifacts) in validator/node code, gated by environment variables and with provisions for self-immunity. While legitimate for controlled testing or chaos experiments, the guidance enables high-impact sabotage if applied in production or by an attacker who can set environment variables or modify code. The file is dangerous as a recipe for supply-chain or insider attacks against consensus networks and should be treated with caution; if present in a codebase it requires strict controls (access, review, CI safeguards, and runtime env var protections) and should not be shipped to production environments without removal or additional hardening.

Confidence: 85%Severity: 80%
Audit Metadata
Analyzed At
Mar 18, 2026, 02:53 AM
Package URL
pkg:socket/skills-sh/ton-blockchain%2Fton-triage-skill%2Fton-bug-triage%2F@fc6295bb4fb3185ea4909afadc081963c60378a3