erc8004-agent-creator
Warn
Audited by Snyk on Apr 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly about scaffolding EVM and Solana agents and includes crypto-specific functionality: it generates or accepts an agent wallet (PRIVATE_KEY in .env), instructs users to fund the wallet (testnet ETH/SOL), and runs an on-chain "register" step via
npm run registerthat uploads metadata to IPFS and mints an Identity Registry NFT. The generated project containssrc/register.tsand related on-chain actions. These are concrete crypto/blockchain operations (wallets, signing, minting transactions), not generic tooling, so it grants direct crypto execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata