erc8004-agent-creator

Warn

Audited by Snyk on Apr 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly about scaffolding EVM and Solana agents and includes crypto-specific functionality: it generates or accepts an agent wallet (PRIVATE_KEY in .env), instructs users to fund the wallet (testnet ETH/SOL), and runs an on-chain "register" step via npm run register that uploads metadata to IPFS and mints an Identity Registry NFT. The generated project contains src/register.ts and related on-chain actions. These are concrete crypto/blockchain operations (wallets, signing, minting transactions), not generic tooling, so it grants direct crypto execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 12, 2026, 08:37 AM
Issues
1