An SDK to develop applications on the Verified Network
The SDK automatically sends a signer private key, encrypted for a package-controlled public key, while processing contract calls and fee quotes. The matching private-key holder can decrypt it.
Package ships high-entropy non-source blobs.
.yarn/install-state.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.yarn/install-state.gzView on unpkgPackage ships compressed or archive-like blobs.
.yarn/install-state.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/abi/assetmanager/Vault.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/contract/index.jsView on unpkgNon-read contract calls extract the signer's private key.
dist/contract/index.jsView on unpkg · L414This report applies to @verified-network/verified-sdk@2.9.6.
See version security history for other recorded verdicts.
Evidence last updated: .
The key is encrypted to a package-embedded public key before transmission.
dist/contract/index.jsView on unpkg · L221Package ships high-entropy non-source blobs.
.yarn/install-state.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.yarn/install-state.gzView on unpkgPackage ships compressed or archive-like blobs.
.yarn/install-state.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/abi/assetmanager/Vault.jsonView on unpkgThe key is encrypted to a package-embedded public key before transmission.
dist/contract/index.jsView on unpkg · L221Non-read contract calls extract the signer's private key.
dist/contract/index.jsView on unpkg · L414Source fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/contract/index.jsView on unpkg