onboarding
Warn
Audited by Snyk on Mar 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly targets cryptocurrency wallet setup and onboarding (checks for "wallet presence + lock status", supports "--wallet-password" or env-based password to auto-unlock a wallet) and exposes a "finance" pack described as "bitflow, defi (mainnet write-capable)". Those are specific crypto/blockchain capabilities (wallet management and mainnet write-enabled DeFi) that can be used to sign and send transactions. This is not a generic tool: it is purpose-built for blockchain financial operations and includes explicit wallet unlocking and mainnet write references, so it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata