blockrun
Warn
Audited by Snyk on Jul 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). SKILL.md describes enabling xAI “Live Search” with
search=True/search_parameters, which at runtime can fetch and ingest outsider-authored free text from external sources (X/web/news) into the model context.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly provisions and controls an on-chain crypto wallet and automatic micropayments: it auto-creates a wallet via setup_agent_wallet(), shows wallet address and QR for funding, reports an on-chain USDC balance, tracks/spends funds (client.get_spending(), client.chat() charges), and instructs funding on the Base network. These are explicit crypto wallet/payment capabilities (wallet creation, balance, address/QR, and automatic spending), i.e., direct financial execution.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata