ethskills
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly instructs the agent to fetch remote instruction files at runtime (e.g., https://ethskills.com/ship/SKILL.md and the base URL pattern https://ethskills.com//SKILL.md), so external content would be loaded and could directly control agent prompts.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). This skill collection explicitly documents crypto payment and wallet tooling: it references the x402 HTTP 402 payment protocol and x402 SDKs (machine-to-machine payments), EIP-3009 gasless token transfers, wallet/multisig guidance and Gnosis Safe for treasuries. These are specific, production-ready crypto payment/wallet capabilities (i.e., tools/protocols meant to send or manage funds), which constitute direct financial execution authority.
Issues (2)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata