create-project-with-grant

Warn

Audited by Snyk on Mar 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly performs an on-chain transaction to create a project and attach a grant (creates 4 attestations in a single tx). It includes blockchain-specific fields (chainId, smart account/transaction in response) and a grant.amount parameter, and shows a concrete API call ("action": "createProjectWithGrant") to execute the transaction via the Karma agent API. This is a specific crypto/blockchain financial operation (on-chain transaction/attestation/funding), not a generic tool, so it grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 3, 2026, 09:26 PM