taproot-multisig
Warn
Audited by Snyk on Mar 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a Bitcoin Taproot multisig coordination tool: it accesses an unlocked wallet to export internal pubkeys, constructs Taproot addresses/derivation paths, verifies and (in coordination with the signing skill) signs BIP-340 Schnorr sighashes for OP_CHECKSIGADD multisig spending, and documents proven mainnet transactions. These are direct crypto financial operations (wallet key management and signing of transaction sighashes) that enable authorization of on‑chain spends. Under the core rule, Crypto/Blockchain signing and wallet access constitute Direct Financial Execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata