polygon-automation

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly for "Polygon Automation" via a Composio "polygon" toolkit and requires an active Polygon connection. It instructs the agent to discover and then execute toolkit tools (via RUBE_SEARCH_TOOLS and RUBE_MULTI_EXECUTE_TOOL) tied to the polygon toolkit. That setup is specifically designed for blockchain/crypto operations (Polygon) and therefore can expose wallet/transaction/signing or token-transfer functionality. This is not a generic HTTP/tool wrapper — it is a purpose-built Polygon toolkit intended to perform on-chain actions, so it meets the "Crypto/Blockchain (Wallets, Swaps, Signing)" criterion.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 01:12 PM