emblem-token-swap
Warn
Audited by Snyk on Apr 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed to perform cryptocurrency value transfers: it provides named swap and bridge tools (e.g., splBuyIntent, ethSwap, baseSwap, polygonSwap, hederaTokensSwap, swapUsingChangeNow, getChangeNowSwapQuote), CLI examples that execute swaps and bridges, balance-checking plus "Execute the Swap" steps, and a required agent wallet package (@emblemvault/agentwallet) implying transaction signing. These are specific crypto/financial execution capabilities (wallet/swaps/bridging), not generic tooling. Although it mentions a user confirmation "safe mode," the skill's primary purpose is to send transactions that move funds.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata