avnu

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The avnu SDK skill is explicitly a DeFi/crypto execution toolkit for Starknet. It exposes concrete transaction-creating and executing functions (executeSwap, executeCreateDca, executeCancelDca, executeStake, executeClaimRewards, executeInitiateUnstake/executeUnstake, account.execute, account.executePaymasterTransaction, executePaymasterTransaction, signPaymasterTransaction, buildSponsoredTx, etc.), requires a Starknet account/private key or wallet connection, and shows patterns for creating and submitting signed blockchain transactions and managing paymaster/API keys for sponsored gas. These are specific, purpose-built capabilities to move funds, create market orders/DCA buys, stake/unstake, and sign/send crypto transactions — matching the "Crypto/Blockchain (Wallets, Swaps, Signing)" and "Send Transaction" criteria.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 09:31 PM