defi-attack-patterns

Fail

Audited by Snyk on Jul 21, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This document is an explicit, actionable DeFi attack playbook providing step‑by‑step instructions for oracle manipulation, flash‑loan drains, governance takeovers, reentrancy drains, MEV extraction, and bridge compromises—clearly enabling malicious exploitation.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an explicit DeFi attack playbook that instructs how to borrow and move on-chain assets (flash borrow/repay, swaps on AMMs, liquidations, governance-token borrows/votes, bridge mint/release flows, MEV front-/back-runs). These are concrete, crypto/blockchain financial actions (flash loans, swaps, governance token manipulation, liquidation and bridge token transfers) — i.e., instructions to execute value-transferring transactions on blockchain protocols. This meets the "Crypto/Blockchain (Wallets, Swaps, Signing)" criterion for Direct Financial Execution.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 21, 2026, 01:23 PM
Issues
2
Security Audit — snyk — defi-attack-patterns