alby-hub

Warn

Audited by Snyk on Jul 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).


MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Yes. The skill is explicitly designed to manage a Lightning/Bitcoin node and includes concrete commands and features that can move funds:
  • "Payments: Pay/make invoices, transactions, lookup, balances, wallet address" — explicit send/pay capabilities.
  • "Swaps: Swap on-chain bitcoin ↔ lightning (swap in / swap out)" — explicit on-chain/lightning asset movement.
  • "Sub-wallets: ... transfer funds in/out, pay from a sub-wallet" — explicit fund transfers between wallets.
  • "LSP: Order a channel up front" and channel open/close operations — actions that allocate or move liquidity.
  • create-app returns a nostrWalletConnectUrl that "grants wallet access" (a connection secret that allows spending). Additionally, the JWT token file grants "full hub API access" which would permit executing those financial operations via the CLI/API.

These are specific, finance-oriented APIs and commands to send funds and perform swaps rather than generic tooling, so this qualifies as direct financial execution authority.

Issues (2)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 03:49 PM
Issues
2
Security Audit — snyk — alby-hub