glam

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a Solana crypto asset management tool with commands and SDK functions to move and manage funds: swaps (JupiterSwap), deposits and trading (DriftProtocol perp/spot), lending/borrowing (KaminoLend), bridging USDC (CCTP), staking, token transfers, and SDK minting/issuing/burning/forceTransfer. The CLI/SDK require a keypair and RPC endpoint and include explicit "swap", "deposit", "bridge-usdc", "transfer", and "client.mint.*" actions that send blockchain transactions. This is a specific financial execution capability (crypto/blockchain wallet, swaps, signing, and asset management), so it meets the Direct Financial Execution definition.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 03:34 PM