ship

Warn

Audited by Snyk on Mar 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 1.00). The skill explicitly instructs the agent to "Fetch" other skill documents at runtime (e.g., https://ethskills.com//SKILL.md), meaning external content from that URL would be loaded during execution and could directly control prompts/instructions.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill is explicitly about building and deploying blockchain dApps that handle tokens, swaps, vaults, lending, and payments. It references concrete crypto primitives and integrations (ERC-20/ERC-721/ERC-4626, SafeERC20, OpenZeppelin, Uniswap/Aerodrome, Aave), wallet flows ("Approve → Execute", multisig / Gnosis Safe), swaps and gas costs, payment contracts (x402), and onchain transfers. Those are specific crypto/blockchain financial capabilities (wallets, swaps, signing, token transfers and deployments) rather than generic tooling. Therefore it grants direct crypto financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 5, 2026, 05:39 PM