openfin-relay

Warn

Audited by Snyk on May 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill provides explicit crypto financial execution capabilities. It documents API endpoints (POST /agent/relay/execute) that sign with the user's wallet, broadcast transactions, and move tokens across chains (bridges, swaps, bridge+call). It supports sending funds to arbitrary recipients, performing cross-chain swaps, and executing destination-chain transactions (txs). These are concrete blockchain transaction and wallet operations (crypto/Blockchain: wallet signing, sending, swapping, bridging), not generic tooling—so it directly moves money/tokens.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 12, 2026, 07:58 PM
Issues
1
Security Audit — snyk — openfin-relay