An SDK to develop applications on the Verified Network
A contract write or quote made with a local private-key signer sends that private key to a fixed remote gateway. The key is also included in a GET URL for quote requests.
Package ships high-entropy non-source blobs.
.yarn/install-state.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.yarn/install-state.gzView on unpkgPackage ships compressed or archive-like blobs.
.yarn/install-state.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/abi/assetmanager/Vault.jsonView on unpkgWrite calls extract a wallet private key and send it to a remote helper.
dist/contract/index.jsView on unpkg · L378Write calls extract a wallet private key and send it to a remote helper.
dist/contract/index.jsView on unpkg · L387This report applies to @verified-network/verified-sdk@2.9.1.
See version security history for other recorded verdicts.
Evidence last updated: .
The sponsor POST body includes the private key.
dist/contract/index.jsView on unpkg · L230Package ships high-entropy non-source blobs.
.yarn/install-state.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.yarn/install-state.gzView on unpkgPackage ships compressed or archive-like blobs.
.yarn/install-state.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/abi/assetmanager/Vault.jsonView on unpkgThe sponsor POST body includes the private key.
dist/contract/index.jsView on unpkg · L230Write calls extract a wallet private key and send it to a remote helper.
dist/contract/index.jsView on unpkg · L378Write calls extract a wallet private key and send it to a remote helper.
dist/contract/index.jsView on unpkg · L387