viem-sweep

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Yes. The skill is explicitly and specifically designed to move crypto assets and execute blockchain transactions: it describes token "sweeping" (moving assets from multiple sources to a destination), strategies that require signing and submitting transactions (Legacy direct transfers, Factory flush, Permit EIP-2612, Auth EIP-3009, EIP-7702 delegation), and requires a WalletClient for signing/sending. It instructs an "admin" to submit batches and references private keys, relayers, and transaction execution flows—all explicit mechanisms for transferring funds on-chain. This meets the definition of Direct Financial Execution (crypto/blockchain wallets and transaction sending).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 09:45 PM