create-project
Warn
Audited by Snyk on Mar 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly interacts with a blockchain: it requires a chainId, creates on-chain attestations (Project + ProjectDetails), and calls a specific Karma agent API action ("createProject") using an API key. This is a purpose-built crypto/blockchain operation (on-chain writes/signing via the protocol), which falls under the "Crypto/Blockchain (Wallets, Swaps, Signing)" category in the core rule. Even though it may not transfer funds, it performs blockchain transactions and is therefore flagged as direct financial execution capability.
Audit Metadata