defi-lending-operator

Warn

Audited by Snyk on Mar 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly exists to "Sign and submit lending/borrowing transactions" on DeFi platforms (Surf Finance, FluidTokens). It includes a concrete command to sign and submit an unsigned transaction (node scripts/sign-and-submit.js --cbor ) and safety rules about private keys and manual confirmation. This is a specific crypto/blockchain transaction signing and submission capability (directly moves funds or initiates financial operations), so it meets the definition of Direct Financial Execution.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 22, 2026, 01:21 AM
Issues
1