@1247/orderly-deposit-withdraw
Warn
Audited by Snyk on Mar 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed to move tokens and manage on-chain funds. It contains concrete, specific financial execution capabilities: smart-contract interactions (ERC20 approve, allowance, vault.deposit), on-chain transactions (depositTx, deposit fee value), wallet signatures (EIP-712 signing for withdrawals and internal transfers, Ed25519 signing for API auth and Solana), REST endpoints to submit withdraw_request and v2/internal_transfer, transfer/withdraw nonces, and cross-chain withdrawal handling. These are direct crypto/blockchain payment and transfer operations (wallets, signing, submitting transfer/withdraw transactions), not generic tooling. Therefore it grants Direct Financial Execution Authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata