analytics-pro

Fail

Audited by Snyk on Apr 20, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill instructs the agent to save and include JWTs and wallet signatures verbatim in request headers/bodies (and to handle signature/private-key-derived values), which requires the LLM to handle secret values directly and risks exfiltration.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly implements a subscription payment flow that moves crypto funds: it uses the x402 payment protocol to charge $10.00 USDC, requires signing a USDC transfer authorization, settles the payment on-chain, and shows example code using an EVM private key / x402Fetch. This is not a generic API caller or browser automation — it is a specific, built-in crypto payment flow that performs real transfers. Therefore it grants direct financial execution capability.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
HIGH
Analyzed
Apr 20, 2026, 12:46 PM
Issues
2
Security Audit — snyk — analytics-pro