crypto-bd-agent
Warn
Audited by Snyk on Jun 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.78). The skill’s runtime workflow includes “Web Scraping”/“Free-First” intelligence gathering (e.g., Firecrawl or similar) and “Community”/forum signals, which typically fetch outsider-authored free-form text from public web pages or third-party posts and then feeds that scraped prose into the LLM for scoring/outreach.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly defines and expects autonomous crypto payment activity: it describes "autonomous payment workflows (x402)", repeated references to "x402 micropayments" (including cost per call and daily budget), rules like "x402 payments ONLY through verified endpoints", and separation of "wallets: payments, on-chain posts, LLM routing". It also covers on-chain actions such as ERC-8004 agent registration and multi-chain wallet management/forensics. These are specific crypto payment/on-chain capabilities (micropayment execution and on-chain registration), not generic tooling, and therefore grant direct financial execution authority.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata