wallet

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill is explicitly designed to manage and move value on the Internet Computer. It includes concrete APIs and commands for converting ICP to cycles, minting cycles (icp cycles mint), topping up canisters (icp canister top-up), calling the cycles ledger and CMC, management canister methods like deposit_cycles and create_canister_with_extra_cycles, and runtime calls to accept and attach cycles (msg_cycles_accept / Cycles.accept). Those are direct blockchain wallet/payment operations (creating wallets/canisters, sending funds/cycles, and performing on-chain transfers), so it grants Direct Financial Execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 10:34 PM