senpi-onboard
Warn
Audited by Snyk on Mar 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed for a crypto trading platform onboarding: it generates or accepts an EVM wallet (using ethers), persists private key/mnemonic locally, and creates/stores an API key and MCP server configuration that enables portfolio management and order execution (Hyperliquid) via the Senpi MCP. It also mandates balance checks, instructs funding with USDC, and sets up credentials that allow the agent to perform trading operations via the MCP. These are specific crypto/wallet and trading integrations (not generic tooling), so it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata