swarm-vault-manager-trading
Warn
Audited by Snyk on Feb 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed to perform crypto financial operations: it provides commands to execute swaps across member wallets (pnpm execute-swap), execute arbitrary smart-contract transactions across swarm member smart wallets (pnpm execute-transaction), includes transaction templates for ERC-20 transfers/approvals/wraps, and exposes SDK methods like client.executeSwap and client.executeSwap/executeTransaction. It requires an API key and targets blockchain token addresses and wallets. These are direct crypto/blockchain transaction capabilities (sending transactions, swaps, and managing wallet funds), so it grants Direct Financial Execution authority.
Audit Metadata