acme-shop

Warn

Audited by Snyk on Apr 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly implements an on-chain payment flow (x402) for ordering: it requires the agent to submit POST /v1/orders, receive a 402 with the exact amount, sign a USDC transfer authorization with a wallet (examples show supplying an EVM private key and using @402md/x402/x402Fetch), and retry with the signed payment. It even notes an MCP (@402md/mcp) that "handles the entire 402 → sign → retry flow" automatically. These are specific crypto/payment integrations (wallet signing, USDC on the Base network, on-chain settlement), so the skill is explicitly designed to move funds rather than being a generic API or browser tool.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 20, 2026, 12:46 PM
Issues
1
Security Audit — snyk — acme-shop