moltycash

Warn

Audited by Snyk on Feb 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed to move money: it provides a CLI to send USDC payments to molty.cash users, supports Base and Solana, requires wallet private keys (EVM_PRIVATE_KEY, SVM_PRIVATE_KEY), and includes a send command (e.g., "npx moltycash send <molty_name> "). This is a specific crypto payment/transaction tool (wallet signing and transfer), not a generic utility, so it grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 18, 2026, 02:50 PM