lightning-channel-factories

Fail

Audited by Snyk on Mar 22, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). The links include an unknown project site on a nonstandard TLD and a GitHub repository owned by a numeric/unknown account (a common indicator of low-reputation or new/malicious publishers), so while one link is a forum post, the combination could be used to distribute untrusted binaries and should be treated as suspicious.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a technical reference and implementation for Lightning Network channel factories and related Bitcoin Layer-2 primitives. It explicitly mentions MuSig2 key aggregation, Schnorr adaptor signatures, HTLC/PTLC forwarding, watchtower breach detection, and support for mainnet — all of which are specific crypto/blockchain signing and channel-management capabilities used to construct and authorize real fund-moving transactions on Bitcoin/Lightning. These are not generic tools; they are explicitly designed for blockchain transaction signing and channel operations, so they grant direct financial execution capability.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 22, 2026, 05:23 PM
Issues
2