solidity-governance
Warn
Audited by Snyk on Feb 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a domain-specific blockchain/DAO governance tool that generates on-chain contracts and deployment scripts for Treasury management, TimelockController, multisig, governance tokens, and Governors. It includes patterns and code to create a Treasury.sol, Timelock-based executors, grant proposer/executor roles, and full propose→vote→queue→execute flows — all of which enable on-chain transaction execution and movement of crypto funds. This is a specific crypto/blockchain financial capability (treasury management, multisig, timelock execution), not a generic tool, so it grants Direct Financial Execution authority.
Audit Metadata