filecoin
Warn
Audited by Snyk on Feb 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is a Lotus (Filecoin) node integration exposing JSON-RPC APIs for mpool (message pool), gas, market, payment channels, and multisig. Those APIs explicitly support creating, signing, and broadcasting Filecoin messages/transactions, managing payment channels and multisig wallets, and interacting with on-chain balances. This is a specific crypto/blockchain financial execution capability (moving tokens, opening/settling payment channels, multisig transactions), not a generic tool, so it grants direct financial execution authority.
Audit Metadata