pendle-plugin

Warn

Audited by Snyk on Oct 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The SKILL.md file contains embedded bash instructions that execute curl to fetch scripts and binaries from GitHub (raw.githubusercontent.com and GitHub releases) at runtime during pre-flight setup, which are operational external dependencies from an unknown/unverified or third-party/official repository context.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 0.70). The skill documents direct financial operations (buying and selling PT/YT tokens, adding and removing liquidity, and minting/redeeming PT+YT pairs on Pendle Finance via on-chain contract calls). These actions execute transfers, trades, and settlement authorization. While the skill instructs the agent to follow a preview/confirmation protocol before executing live writes with --confirm, these rules are agent instructions embedded in the skill text rather than independent access controls enforced by the service or execution layer. Consequently, no qualifying independent authentication or authorization mechanism is established for the direct financial routes.

Issues (2)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 8, 2026, 08:56 PM
Issues
2