lightning-factory-explainer
Fail
Audited by Snyk on Aug 10, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). The GitHub repo is hosted under a numeric/unknown account and the project website uses a nonstandard .win domain—both are unverified third‑party sources that may host executables or releases from an untrusted author and lack clear community vetting, so they present a higher risk for distributing malware.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly and specifically focused on Bitcoin and Lightning Network financial infrastructure (channel factories, shared UTXO management, onboarding patterns) and references cryptographic signing and key-aggregation (MuSig2/BIP-327). These topics are specific to cryptocurrency transaction construction, signing, and funds management rather than being a generic developer or browser tool — therefore it grants the agent domain-specific capability related to crypto financial execution.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata