taproot-multisig

Warn

Audited by Snyk on Mar 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a Bitcoin Taproot multisig coordination tool: it accesses an unlocked wallet to export internal pubkeys, constructs Taproot addresses/derivation paths, verifies and (in coordination with the signing skill) signs BIP-340 Schnorr sighashes for OP_CHECKSIGADD multisig spending, and documents proven mainnet transactions. These are direct crypto financial operations (wallet key management and signing of transaction sighashes) that enable authorization of on‑chain spends. Under the core rule, Crypto/Blockchain signing and wallet access constitute Direct Financial Execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 14, 2026, 07:27 PM
Issues
1