adshares

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an integration for AdShares, a blockchain-based advertising marketplace, and its own overview explicitly lists "Wallet" and "Transaction". It provides CLI commands to discover and run pre-built actions via Membrane (membrane action run ...) and to proxy arbitrary API requests (membrane request ...) with full HTTP methods (POST/PUT/PATCH/DELETE) and JSON bodies. Membrane manages authentication/credentials so the agent can invoke connector actions or proxied endpoints that handle wallet operations or submit blockchain transactions. Because the skill is specifically tied to a crypto/blockchain service and exposes wallet/transaction functionality (and mechanisms to run actions or send transaction-like requests), it constitutes direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 08:56 AM