pancakeswap-v3-plugin
Warn
Audited by Snyk on Oct 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The workflow queries public JSON-RPC endpoints and subgraphs, which return data containing external contract output or subgraph records, but does not monitor or consume unstructured outsider-authored free text feeds without specific target item selection.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill includes inline shell commands in SKILL.md that fetch and execute remote scripts and binaries from GitHub (
raw.githubusercontent.comand GitHub Releases) via curl at runtime.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 0.70). The skill provides commands to swap tokens and manage concentrated liquidity pools on PancakeSwap V3 across multiple chains, executing direct on-chain financial operations (
swap,add-liquidity,remove-liquidity) via wallet contract calls. While the documentation describes confirmation protocols and manual preview steps, these instructions rely entirely on the AI agent following them rather than an independent service- or execution-layer authentication/authorization gate that prevents unauthorized signing.
Issues (3)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata