signing

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly provides cryptographic signing using wallet keys (Stacks SIP-018, Stacks message signing, Bitcoin BIP-137/BIP-322, BIP-340 Schnorr signing, and Nostr NIP-06). Several commands require an unlocked wallet and specifically include signing raw 32-byte digests for BIP-340 ("schnorr-sign-digest") which is described as usable for Taproot script-path spending and multisig coordination — i.e., authorizing on-chain spending. This is a purpose-built crypto signing tool (wallet-backed signing), which falls squarely under the "Crypto/Blockchain (Wallets, Swaps, Signing)" category of Direct Financial Execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 11:12 PM