controller-native

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed for blockchain financial operations. It provides wallet/owner creation from a private key, local keypair signing, RPC URLs for Starknet mainnet, and direct APIs to execute/send transactions (e.g., session.executeFromOutside, controller.execute, ControllerAccount.newHeadless with owner privateKey). These are explicit crypto wallet and transaction-sending capabilities (signing and broadcasting), which constitute Direct Financial Execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 03:06 AM