battlechain-tutorial
Warn
Audited by Snyk on Mar 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a specialized BattleChain deployment assistant that explicitly generates and modifies on-chain deployment scripts and Safe Harbor/agreement scripts. It references and mandates use of chain-specific deploy functions (e.g., bcDeployCreate2/bcDeployCreate()/bcDeployCreate3()), a deployer address, creation/adoption of Safe Harbor agreements via createAndAdoptAgreement(), a RequestAttackMode transaction, and explicit "seeding logic" to transfer a user-specified token amount. It also collects an asset recovery address and bounty/payment parameters (percentage, caps, retainable) which are applied in on-chain agreement/deployment flows. These are domain-specific blockchain transaction actions (deploying contracts, seeding tokens, registering agreements, and directing recovered/bounty funds) — not generic tooling — and therefore provide direct capability to execute crypto/financial operations on-chain. Accordingly this skill grants Direct Financial Execution Authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata