agenticbets

Warn

Audited by Snyk on Sep 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The agenticbets skill fetches prediction market metadata and lists from an external API (https://agenticbets.dev/api/bankr/markets), which could potentially contain outsider-submitted market descriptions, symbols, or creator addresses read at runtime.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The skill makes runtime HTTP requests to the AgenticBets API (https://agenticbets.dev/api/bankr/markets) to fetch market data and token addresses used to construct on-chain bets and transactions. Since agenticbets.dev is an untrusted third-party personal/project domain rather than a recognized official vendor infrastructure, this constitutes an operational dependency with weak/unknown provenance.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill documentation explicitly describes tools and workflows for placing financial prediction bets using USDC, interacting with smart contracts on Base via the Bankr Submit API, approving token spends, and claiming financial winnings. This directly falls under cryptocurrency and market order financial execution capabilities.

Issues (3)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 24, 2026, 04:44 AM
Issues
3
Security Audit — snyk — agenticbets