Caveat verdict
stove_maker_api
stove-maker-api
A DeFi market-maker API client for Stove Protocol using a JWT token to manage orders and positions on its declared endpoints; credential access is narrowly scoped to its own service and behavior is transparent.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (4)
Long base64 string (100+ chars) — likely obfuscated payload
references/API Authorization.md · code · 0x8f3d2e1c4b5a6f7e8d9c0b1a2f3e4d5c6b7a8f9e0d1c2b3a4f5e6d7c8b9a0f1e2d3c4b5a6f7e8d
Base64 decode (atob) — may hide malicious payloads
references/API Authorization.md · code · atob(
Possible hardcoded credential
references/EIP-712 Order Signature.md · prose · downgraded · Token
=
"your_jwt_token
Opens WebSocket connection
references/Order Status Event Push.md · code · WebSocket
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.