nexus-elements-deposit
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a deposit/swap-and-execute widget for blockchain tokens. It requires initializing an EIP-1193 wallet provider, constructs and returns on-chain transaction data (to, data) and token approval details, and uses an SDK function named sdk.swapAndExecute. The executeDeposit callback and other flows are specifically for depositing tokens, handling approvals, and executing on-chain swaps — i.e., moving crypto funds. This matches the "Crypto/Blockchain (Wallets, Swaps, Signing)" criterion for Direct Financial Execution.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata