teach-algorand-x402

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).


MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly implements on-chain payment flows using Algorand: clients build and sign Algorand transaction groups, facilitators simulate, sign fee-payer transactions, and submit atomic groups to the Algorand network. It references private keys (AVM_PRIVATE_KEY), algod endpoints, SDK packages (algosdk, x402-avm), and an online facilitator URL. These are specific crypto/blockchain payment and signing actions (wallet/private-key signing and submitting transactions), which constitute direct financial execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 12:48 PM