lightning-channel-factories
Fail
Audited by Snyk on Mar 22, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). The links include an unknown project site on a nonstandard TLD and a GitHub repository owned by a numeric/unknown account (a common indicator of low-reputation or new/malicious publishers), so while one link is a forum post, the combination could be used to distribute untrusted binaries and should be treated as suspicious.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a technical reference and implementation for Lightning Network channel factories and related Bitcoin Layer-2 primitives. It explicitly mentions MuSig2 key aggregation, Schnorr adaptor signatures, HTLC/PTLC forwarding, watchtower breach detection, and support for mainnet — all of which are specific crypto/blockchain signing and channel-management capabilities used to construct and authorize real fund-moving transactions on Bitcoin/Lightning. These are not generic tools; they are explicitly designed for blockchain transaction signing and channel operations, so they grant direct financial execution capability.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata