log-lightning-issues

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is specifically focused on Bitcoin Lightning Network integration and mentions concrete crypto-related components: LND macaroons, RPC exposure, invoice settlement verification, payment timeout handling, fee caps, idempotency for payment requests, and related primitives (/lightning, /fix-lightning). These are explicit, domain-specific elements of a crypto payments stack (node auth, payment/invoice handling and node control), not generic tooling. Even though this particular skill creates GitHub issues (an auditor/issue-creator), its primary domain is Lightning (a crypto payment system) and it references specific wallet/node controls and payment handling gaps — meeting the "Crypto/Blockchain (Wallets, ... Signing)" criterion. Therefore it should be flagged as granting (or being directly related to) financial execution authority risk.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 11:14 AM