money-mode-router
Warn
Audited by Snyk on Mar 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed around Kraken financial products and maps user intent to concrete money-moving modes: payments, investing, active-trading, onchain (explicitly described as "Kraken spot funding endpoints for deposits, withdrawals, and wallet transfers"), and automation. It references Kraken account context via SEREN_API_KEY and configurable publishers such as KRAKEN_TRADING_PUBLISHER / kraken-spot-trading, indicating integration points that would invoke trading/funding APIs. Although the router claims to recommend and let Kraken API permissions enforce availability, the primary and explicit purpose is to select and route to API-backed financial actions (trades, deposits/withdrawals, wallet transfers). This meets the "Direct Financial Execution" criteria (crypto/blockchain wallet/funding endpoints and market/trading publishers).
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata