smart-accounts-kit
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). This skill is explicitly a Web3 financial execution toolkit. It provides concrete APIs and examples to create smart accounts, sign and send transactions (e.g., sendUserOperation, sendTransactionWithDelegation, bundlerClient.sendUserOperation), construct and redeem delegations that transfer ERC‑20 and native tokens, request ERC‑7715 execution/transfer permissions, and implement automated patterns (DCA bots, backend redemption, session accounts) that perform on‑chain token transfers. The documentation names specific financial actions (erc20TransferAmount, nativeTokenTransfer, redeemDelegations, transfer calldata) and concrete functions/clients for submitting transactions and swaps. These are specific tools to move value, not generic utilities.
Audit Metadata