opensea
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). At runtime, the
opensea-apiworkflow ingests outsider-authored free text viaget_collections/get_items/get_tokensauto-resolvequeryparameters (and alsosearch_*queries) and can ingest untrusted user-generated metadata returned by OpenSea APIs (e.g., NFT names/descriptions) into the LLM context.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly references and routes to sub-skills that perform on-chain financial actions: buy/sell NFTs and sweeps, fulfill listings, ERC20 token swaps via a DEX aggregator, and configuring wallet signing (Privy/Turnkey/Fireblocks/Bankr). These are specific crypto/blockchain transaction and signing capabilities (i.e., directly moving assets or signing transactions), so it constitutes Direct Financial Execution authority.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata