money-mode-router

Warn

Audited by Snyk on Mar 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed around Kraken financial products and maps user intent to concrete money-moving modes: payments, investing, active-trading, onchain (explicitly described as "Kraken spot funding endpoints for deposits, withdrawals, and wallet transfers"), and automation. It references Kraken account context via SEREN_API_KEY and configurable publishers such as KRAKEN_TRADING_PUBLISHER / kraken-spot-trading, indicating integration points that would invoke trading/funding APIs. Although the router claims to recommend and let Kraken API permissions enforce availability, the primary and explicit purpose is to select and route to API-backed financial actions (trades, deposits/withdrawals, wallet transfers). This meets the "Direct Financial Execution" criteria (crypto/blockchain wallet/funding endpoints and market/trading publishers).

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 21, 2026, 02:44 AM
Issues
1