insforge-integrations
Warn
Audited by Snyk on May 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly includes a "Payment facilitators (x402)" category and detailed, provider-specific payment flow (OKX x402). It requires client-side signing of EIP-3009 authorizations, server forwarding of the signed payload to facilitator /verify and /settle endpoints, and notes that settlement "takes money onchain" before DB insert. It also contains operational guidance for real funds (web3 API keys, DOMAIN_SEPARATOR checks, UNIQUE tx_hash, MOCK_OKX_FACILITATOR for dev). These are concrete, payment-specific APIs and onchain settlement steps intended to move money, not generic tooling.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata