return-funds
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed to move money. It is a crypto wallet refund skill (mentions XNO) that calls specific send/refund APIs and wallet operations: e.g. payment_request_refund with execute:true, wallet_send, wallet_set_allowance, wallet_history, validate_address. The workflow instructs confirming a destination then executing a send and reporting the send hash — i.e., it performs transaction signing/sending. These are direct financial execution capabilities (crypto wallet transfers), not generic utilities.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata