spendguard-strict-budget-runner

Warn

Audited by Snyk on Feb 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill explicitly exposes APIs/CLI for creating agent identities and setting/topping budgets (e.g., "spendguard budget set --agent <agent_id> --limit 5000 --topup 5000", scripts/bootstrap_strict_budget.py, and "spendguard budget get"). It describes enforcing/decrementing hard budget caps and top-ups — i.e., programmatic updates to monetary budget limits and balance. That is a specific financial operation (managing/updating budgets), not a generic tool, so it qualifies as Direct Financial Execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 19, 2026, 02:49 PM