almanak-strategy-builder

Warn

Audited by Snyk on Apr 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a DeFi trading strategy builder whose primary purpose is to create and run on-chain intents that move funds. The documentation defines Intent.swap, Intent.lp_open, Intent.borrow/repay, Intent.perp_open/perp_close, Intent.bridge, Intent.vault_deposit/redeem, flash loans, staking, wrapping/unwrap, cross-chain transfers, etc. It includes CLI commands to run strategies (including live runs and paper trading on forks), guidance on wallets/.env (private key for local testing), Zodiac/Safe wallet permission generation, and notes about transaction execution, retries, and gas/slippage handling. These are concrete, crypto/blockchain transaction primitives (send transaction / move assets), not generic tooling, so it grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 02:45 AM
Issues
1