indigo-oracle

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). This skill is explicitly about blockchain financial operations: it manages an interest oracle for on-chain iAssets (iUSD, iBTC, iETH, iSOL) on Cardano. The listed MCP tools (feed_interest_oracle, start_interest_oracle) return unsigned transactions for signing and require a Cardano wallet address and operator public key—i.e., they construct blockchain transactions that, once signed/submitted, will effect on-chain financial state. That matches the "Crypto/Blockchain (Wallets, Swaps, Signing)" criterion for Direct Financial Execution rather than a generic capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 02:19 AM