foundry-poc

Fail

Audited by Snyk on Apr 1, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The skill explicitly instructs producing verified, runnable exploit tests that demonstrate and quantify draining funds from EVM contracts (clear facilitation of financially harmful exploits), which is high-risk and can be directly used to commit theft; it does not show typical backdoor/exfiltration code but its intent is to create actionable attacks.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly targeted at EVM blockchain operations and is designed to create runnable exploit tests that transfer and drain funds (e.g., assertions that "attacker drained 10 ETH", balance checks, and tests that prove net fund loss). This is not a generic tool: it specifically constructs transactions and attacker/victim scenarios using Foundry/forge to move and prove movement of crypto assets in tests. That falls under Crypto/Blockchain execution capabilities (wallet/transaction behavior) and thus meets the criteria for Direct Financial Execution.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 1, 2026, 10:39 PM
Issues
2
Security Audit — snyk — foundry-poc