build-web3
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Within the required “Quicknode MCP” runtime surface, the assistant can call MCP tools that fetch live blockchain/RPC data (e.g.,
call-rpc) and returns upstream response text to the LLM, which can include attacker-controlled values when reading arbitrary on-chain/contract data.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly for building Web3 apps and references transaction-signing and swap operations (intake question asks about signing transactions/run swaps), includes Quicknode's Swap API and Admin/API surfaces, and discusses account/endpoint/provider management. Those are specific crypto/financial execution capabilities (sending transactions, swaps, managing accounts), not generic tooling, so it grants direct financial execution authority.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata