openocean
Warn
Audited by Snyk on Sep 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The workflow fetches data from the OpenOcean API (a third-party DEX aggregator service), which can return token metadata, quotes, and messages containing free text that the agent processes.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (medium risk: 0.30). The skill makes runtime API calls to open-api.openocean.finance and pro-openapi.debank.com for quotes and token data under common/reputable third-party provenance.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill documentation explicitly includes functionality for executing cryptocurrency token swaps via the OpenOcean DEX aggregator (
openocean_swap), managing ERC20 token approvals, and interacting with blockchain wallets. This represents direct financial execution authority (Crypto/Blockchain Swaps/Signing).
Issues (3)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata