ckbtc
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a crypto payment/asset integration for ckBTC. It contains specific, purpose-built financial APIs and functions that move value: calling the ckBTC minter to mint on BTC deposits (get_btc_address, update_balance), executing ledger transfers (icrc1_transfer), approving and instructing withdrawals to Bitcoin (icrc2_approve, retrieve_btc_with_approval), and balance checks. It even includes concrete canister IDs and transfer/withdrawal flows with fees and minimums. This is clearly designed to send, receive, and convert real value (BTC/ckBTC), so it grants Direct Financial Execution authority.
Audit Metadata