polybaskets-skills

Warn

Audited by Snyk on May 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).


MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill pack is explicitly for interacting with a blockchain prediction market and includes direct crypto financial operations: creating wallets, checking balances, approving token spends (BetToken/Approve), placing on-chain bets (BetLane/PlaceBet), claiming payouts (BetLane/Claim), and managing gas vouchers (POST to voucher backend to fund 500 VARA). It uses a wallet CLI (vara-wallet) to sign and send transactions and contains step-by-step commands that move tokens and execute on-chain transactions. This is specifically designed to move money/assets on-chain, not a generic tool, so it meets the Direct Financial Execution criteria.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 3, 2026, 10:05 AM
Issues
2