darksol-random-oracle

Fail

Audited by Snyk on Jul 5, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill requires the agent to accept and include user-supplied authentication headers (wallet address and a cryptographic signature) verbatim in HTTP requests, which forces the LLM to handle and output secret-like credentials.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly requires on-chain crypto payments and wallet signatures: it documents x402 USDC payment on Base (with amounts, pay-to address, and token address), instructs completing the x402 payment flow when HTTP 402 is returned, and requires signing a message (wallet signature) for holder-free access. These are concrete blockchain payment/signing operations (wallet signing and sending USDC transactions), which constitute direct financial execution capability.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
HIGH
Analyzed
Jul 5, 2026, 02:12 PM
Issues
2
Security Audit — snyk — darksol-random-oracle