@1390/woofi-swap
Warn
Audited by Snyk on Apr 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a crypto swap/bridge API. It provides endpoints to build and execute token swaps and cross-chain swaps (POST /v2/swap and POST /v2/cross_chain/swap), returns ready-to-sign tx_steps, checks approvals, and constructs transaction data for wallet signing and on-chain execution. This is a specific financial execution capability (crypto/blockchain: swaps, transaction building/signing). Even though the API returns unsigned txs (wallet signs), the primary purpose is moving value on-chain, not a generic tool. Therefore it meets the "Direct Financial Execution" criteria.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata