AGENT LAB: SKILLS

monetize-service

Warn

Audited by Snyk on Feb 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed to accept and settle payments in USDC on the Base blockchain. It instructs initializing and authenticating a crypto wallet, retrieving a receiving Ethereum address, installing and using the x402-express payment middleware that enforces per-request USDC charges, and optionally wiring a Coinbase CDP facilitator (requiring CDP_API_KEY_ID and CDP_API_KEY_SECRET). It also includes CLI commands to inspect and make payments (npx awal@latest x402 pay). These are specific crypto payment integrations (wallet addresses, token, network, payment middleware, and facilitator API keys), so the tool's primary and explicit purpose is moving money.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 18, 2026, 02:57 AM