hydra-head-operator
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly controls Cardano Layer-2 "Hydra" head operations that produce and finalize on-chain UTxO changes. It includes commands and APIs to commit UTxOs, submit L2 transactions, close heads (begin contestation) and fanout to L1, and references cardano-cli usage and required signing keys (cardano.sk, hydra.sk). These are concrete blockchain transaction operations (including signing and moving funds/UTxOs) — not generic tooling — and therefore constitute direct crypto/blockchain financial execution capability.
Audit Metadata