adding-builder-codes

Warn

Audited by Snyk on Mar 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill is explicitly and specifically about modifying and attributing on-chain transactions (Base L2) by appending ERC-8021 builder-code suffixes to transaction calldata. It integrates with crypto-specific libraries and wallet APIs (Wagmi, Viem, ethers.js, window.ethereum, Privy, smart wallet sendCalls) and its stated purpose is to enable attribution and earn referral fees on transactions. That is a targeted blockchain/crypto financial capability (affecting transaction data and attribution), not a generic tool — so it meets the criteria for Direct Financial Execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 04:43 PM