liberfi-auth

Warn

Audited by Snyk on Apr 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly tied to crypto wallet-backed operations: it provisions and reports server-owned EVM and Solana TEE wallets (evmAddress/solAddress), supports agent key-based login for automated environments, signs authentication payloads with a local key, and references swap/tx commands and on-chain operations that use the server-managed wallets. Although this file is an auth module, it is specifically designed for a crypto financial platform and enables agents to obtain the JWT/session that permits programmatic on-chain (swap/tx) activity. Per the rules, crypto/wallet integrations count as Direct Financial Execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 22, 2026, 08:04 PM
Issues
1