ros-bridge
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly includes a paid-services/payment subsystem. It provides an x402-wrapper and a createX402RobotServer API that accepts an escrowAddress (0x...), per-call pricing, and an example where clients pay 0.005 USDC via HTTP 402 to fetch data. These are specific payment/invoicing primitives (pricing, escrow address, charge-per-call, and a paid-client fetch) — i.e., APIs to collect/route funds — not generic tooling. This meets the "Direct Financial Execution" criteria.
Audit Metadata