Sato Hub
← Sato Check

Sato Check · Package

merx

npm:merx · as of 2026-09-26

Does it take your key?
declared
It asks for a private key or seed phrase in its setup.
The project says so — README, config, env list or tool description.
Does your key leave?
observed
Not observed — no planted key left during install and start-up, under our test conditions — code paths that only run later, or only on a trigger, are not covered.
We ran it with planted test keys and saw it.
Can it move funds on its own?
declared
Yes — 13 actions can sign or send funds when called: create_order (trade, limit unknown); transfer_trx (transfer, limit unknown); transfer_trc20 (transfer, limit unknown); approve_trc20 (approve, limit unknown); ….
The project says so — README, config, env list or tool description.
What changed?
no evidence
First profile of this subject — nothing to compare yet.
No evidence line on file for this question yet.

Is this your project? Respond →Dispute this reading

Hosts contacted

HostWhenRoleEvidence
registry.npmjs.orginstallregistryobserved
Evidence (15 lines)
  • observedO-hosts2026-09-25

    registry.npmjs.org was contacted during install (registry).

    sandbox:obs_a605df298c4fe9e0

  • declaredD-env-key2026-09-26

    Setup names TRON_PRIVATE_KEY as something to provide.

    deploy_spec.requires

  • declaredD-fund-tool2026-09-26

    Tool create_order is described as a trade action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool transfer_trx is described as a transfer action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool transfer_trc20 is described as a transfer action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool approve_trc20 is described as a approve action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool execute_swap is described as a swap action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool deposit_trx is described as a trade action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool enable_auto_deposit is described as a trade action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool pay_invoice is described as a transfer action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool create_paid_order is described as a trade action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool create_standing_order is described as a trade action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool cancel_standing_order is described as a trade action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool withdraw is described as a withdraw action.

    tools/list

  • declaredD-fund-tool2026-09-26

    Tool resource_broadcast is described as a sign action.

    tools/list

Limits

  • The traced lane has not run on this version: registry answered HTTP 404 for merx
  • Traced analysis follows flows inside one module only; a key handed from one module to another is not followed.
  • Traced lane did not run: registry answered HTTP 404 for merx.
  • Key egress not observed during install and start-up, under our test conditions — code paths that only run later, or only on a trigger, are not covered.
  • Sandbox: DNS queries made directly by the target are not logged; hosts are recorded from proxied HTTP(S) requests and CONNECTs..
  • Sandbox: Code that ignores HTTP(S)_PROXY has no route out of the sandbox, so its attempts are not captured..

A profile describes what we read and ran, with dates. It is not a safety rating, an audit or an endorsement, and "not found" is not "not there".

sato.custody/v1 · custody-1

Maintain this project? Respond to this reading

Loading sign-in…