filecoin

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is a Lotus (Filecoin) node integration exposing JSON-RPC APIs for mpool (message pool), gas, market, payment channels, and multisig. Those APIs explicitly support creating, signing, and broadcasting Filecoin messages/transactions, managing payment channels and multisig wallets, and interacting with on-chain balances. This is a specific crypto/blockchain financial execution capability (moving tokens, opening/settling payment channels, multisig transactions), not a generic tool, so it grants direct financial execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 09:46 PM