caw-eval

Warn

Audited by Snyk on Apr 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).


MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly built to evaluate CAW (Cobo Agentic Wallet) agents on transaction-related scenarios. Evidence:
  • Recipe 模式 is described as "交易构建评测" and scoring explicitly includes tx_construction_correctness and tx_submission_success.
  • It states "仅评估交易是否被正确构建/提交" and the dataset is Ethereum Sepolia with cases: transfer / swap / lend / dca — i.e., on-chain financial operations.
  • Server setup references caw/onboarding/充值/验证 and the orchestration dispatches agents to run these transaction scenarios.

This is not a generic automation tool: its primary and explicit purpose includes constructing and submitting crypto transactions. Under the core rule (crypto/wallets/swaps/signing/transaction submission), this constitutes Direct Financial Execution capability.

Issues (2)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 30, 2026, 02:21 AM
Issues
2