insforge-integrations

Warn

Audited by Snyk on May 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly includes a "Payment facilitators (x402)" category and detailed, provider-specific payment flow (OKX x402). It requires client-side signing of EIP-3009 authorizations, server forwarding of the signed payload to facilitator /verify and /settle endpoints, and notes that settlement "takes money onchain" before DB insert. It also contains operational guidance for real funds (web3 API keys, DOMAIN_SEPARATOR checks, UNIQUE tx_hash, MOCK_OKX_FACILITATOR for dev). These are concrete, payment-specific APIs and onchain settlement steps intended to move money, not generic tooling.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 7, 2026, 09:02 AM
Issues
1