blockrun

Warn

Audited by Snyk on Jul 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). SKILL.md describes enabling xAI “Live Search” with search=True/search_parameters, which at runtime can fetch and ingest outsider-authored free text from external sources (X/web/news) into the model context.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly provisions and controls an on-chain crypto wallet and automatic micropayments: it auto-creates a wallet via setup_agent_wallet(), shows wallet address and QR for funding, reports an on-chain USDC balance, tracks/spends funds (client.get_spending(), client.chat() charges), and instructs funding on the Base network. These are explicit crypto wallet/payment capabilities (wallet creation, balance, address/QR, and automatic spending), i.e., direct financial execution.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 05:45 AM
Issues
2
Security Audit — snyk — blockrun