foundry-cast

Fail

Audited by Snyk on Sep 5, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The skill prompt instructs the agent to use --private-key 0xYOURKEY as a command-line argument for the cast send command, which encourages passing private keys directly in generated commands.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill documents Foundry's cast command-line utility for interacting with Ethereum-compatible chains. It includes capabilities for sending blockchain transactions (specifically cast send which signs and broadcasts transactions using a private key and RPC URL), falling under the crypto/blockchain execution criteria (wallets, swaps, signing, transactions).

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
HIGH
Analyzed
Sep 5, 2026, 10:39 PM
Issues
2
Security Audit — snyk — foundry-cast