use-developer-controlled-wallets

Warn

Audited by Snyk on Mar 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed for crypto wallet management and transaction execution. It documents an SDK to create and manage developer-controlled wallets, holds entity private keys, and includes explicit actions for "transfer tokens" and "check balance" (with references for "Transfer Tokens / Check Balance of Wallet"). It requires an API key and entity secret, describes transaction states, idempotency for mutating requests, and security rules around executing transfers. These are specific blockchain/crypto transaction capabilities (wallet custody and sending tokens), which meet the Direct Financial Execution criteria.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 12, 2026, 10:00 PM
Issues
1