lifi

Warn

Audited by Snyk on Jun 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill documents the LI.FI API, which is explicitly a crypto execution platform: it returns ready-to-sign transactionRequest objects (GET /quote, POST /advanced/stepTransaction), guides ERC-20 approvals and signing & sending transactions, supports swaps/bridges and Composer one-click deposits/withdrawals into DeFi protocols, exposes intent/order submission (order.li.fi) including signing flows, and even provides integrator withdrawal transactionRequests. These are specific blockchain/crypto transaction execution primitives (create/sign/send transactions, submit orders, withdraw funds), i.e., direct financial execution capabilities.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 18, 2026, 12:26 AM
Issues
1
Security Audit — snyk — lifi