orderly-one-dex
Warn
Audited by Snyk on Apr 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly supports on-chain crypto payments and wallet signing flows. The "Graduation" workflow requires sending ERC-20 transfers (USDC/USDT/ORDER) to a receiverAddress, saving the tx hash, and calling POST /api/graduation/verify-tx to verify the payment. It also requires signing EIP-712/EIP-191 messages and registering admin wallets (including multisig flows and finalizing admin wallet via API). These are specific crypto/blockchain transaction and signing operations (not generic actions), so the skill grants direct financial execution capabilities.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata