kasia

Fail

Audited by Snyk on Jun 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). This is an unknown GitHub repository/user providing a third‑party "skill" that would be installed/executed (via npx/clawhub), so it can run arbitrary code and lacks indicators of being an official or well‑audited source.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill is explicitly a blockchain-specific capability: it sends and receives encrypted on-chain messages on the Kaspa blockchain. Sending on-chain messages requires creating/submitting transactions and typically involves signing with a wallet/private key. Because it directly interacts with a blockchain (crypto transaction-level operations), it constitutes a crypto/blockchain execution capability and should be treated as direct financial execution authority.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 16, 2026, 01:03 AM
Issues
2
Security Audit — snyk — kasia