1inch-aqua

Warn

Audited by Snyk on Aug 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Skill aqua read actions (maker_stats, list_maker_strategies, strategy_overview/activity/volume, list_opened) can ingest outsider-authored free text when the runtime workflow accepts user-supplied parameters (e.g., maker/app/strategyHash and feed selection) to fetch analytics/feeds from the provider.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly exposes crypto transaction actions: "build_ship", "build_dock", "build_swap" and describes non-custodial execution where the user's wallet signs and, when connected via WalletConnect, transactions are sent through the connected wallet (user approves each prompt). These are specific blockchain wallet/swap/signing capabilities (direct financial execution).

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 14, 2026, 09:35 PM
Issues
2
Security Audit — snyk — 1inch-aqua