walrus-blob-lifecycle
Warn
Audited by Snyk on Jul 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). This skill explicitly instructs the agent to fetch live documentation at runtime (e.g., https://docs.wal.app/docs/walrus-client/managing-blobs and https://docs.wal.app/docs/large-uploads) and to "fetch the relevant page before answering," so remote content from those URLs would directly control the agent's prompts/behavior.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly includes on-chain funding and token-spending operations. Examples: "walrus fund-shared-blob --blob-obj-id <SHARED_OBJ_ID> --amount <WAL_AMOUNT>" and the storage-pool workflow ("fund a pool", "walrus store ... --storage-pool <POOL_ID>") describe funding pools and blobs drawing from funds. These are crypto/blockchain financial actions (spending on-chain tokens and funding pools/shared objects), so the skill provides direct financial execution capabilities.
Issues (2)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata