starchild-auth
Warn
Audited by Snyk on Aug 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Required runtime ingests outsider-authored free text via chat message inputs sent to
/chat/stream(SSE) and queued/chat/streammessages, then processes streamed tool outputs/text deltas from that interaction.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The SKILL.md includes CDN script tags that fetch and execute remote JavaScript at runtime (e.g. https://unpkg.com/starchild-auth-sdk/dist/starchild-auth.umd.cjs and its mirror https://registry.npmmirror.com/starchild-auth-sdk/latest/files/dist/starchild-auth.umd.cjs), which are runtime external dependencies that execute remote code.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly exposes payment and financial APIs: it includes Stripe Checkout session creation (POST /api/stripe/create-session), Coinbase Onramp session creation, gift-card redemption, points-to-credits exchange, KYC/payment setup intents, and wallet management (create/delete wallets, exportPrivateKey, portfolio & onramp). Those are specific payment/crypto operations (payment gateways, onramp, wallet private-key export, credit topups), i.e. direct financial execution capabilities requiring credit:write scope.
Issues (3)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata