l2s
Warn
Audited by Snyk on Mar 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly about Ethereum Layer‑2s and includes concrete, finance-executing artifacts: RPC endpoints, bridge URLs (official and fast bridges), dominant DEXs and swap/bridge providers, verified contract addresses, and a deployment command that uses --private-key (forge create ... --private-key $PRIVATE_KEY) — i.e., an explicit example of signing/sending on‑chain transactions. These are specific crypto/blockchain tools and instructions that enable sending transactions, bridging funds, and interacting with wallets/contracts (not generic tooling). Therefore it grants Direct Financial Execution capability.
Audit Metadata