web3-x402

Warn

Audited by Snyk on Apr 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly implements wallet-based payments and on-chain USDC settlement: it describes SIWX/SIWE/SIWS wallet auth, "Credit mode: pre-charge USDC → off-chain credit deduction," "PPU mode: per-request on-chain USDC settlement," steps to ask for a wallet address and show estimated USDC cost, flows to "Charge USDC," generate payment-signatures, and sign & pay per request. These are specific crypto/payment operations (sending/changing balances and signing payments), not generic tooling, so it grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 3, 2026, 09:53 AM
Issues
1