An SDK to develop applications on the Verified Network
Runtime transaction and quote methods send an encrypted signer private key to a vendor-controlled sponsor service. This occurs without an explicit key-export parameter on the invoked contract operation.
Package ships high-entropy non-source blobs.
.yarn/install-state.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.yarn/install-state.gzView on unpkgPackage ships compressed or archive-like blobs.
.yarn/install-state.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/abi/assetmanager/Vault.jsonView on unpkgRuntime code extracts a signer's private key and encrypts it with a bundled public key.
dist/contract/index.jsView on unpkg · L240Supported-chain contract calls automatically select the gasless path when a private-key signer is present.
dist/contract/index.jsView on unpkg · L414This report applies to @verified-network/verified-sdk@2.9.4.
See version security history for other recorded verdicts.
Evidence last updated: .
The encrypted private key is sent to the vendor gateway in a GET URL query parameter.
dist/contract/index.jsView on unpkg · L463Package ships high-entropy non-source blobs.
.yarn/install-state.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.yarn/install-state.gzView on unpkgPackage ships compressed or archive-like blobs.
.yarn/install-state.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/abi/assetmanager/Vault.jsonView on unpkgRuntime code extracts a signer's private key and encrypts it with a bundled public key.
dist/contract/index.jsView on unpkg · L240Supported-chain contract calls automatically select the gasless path when a private-key signer is present.
dist/contract/index.jsView on unpkg · L414The encrypted private key is sent to the vendor gateway in a GET URL query parameter.
dist/contract/index.jsView on unpkg · L463