@1826/woofi-swap-optimizer

Warn

Audited by Snyk on Mar 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).


MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed to execute cryptocurrency swaps. It requires loading a wallet policy, checking wallet balances, constructing an on-chain WOOFi swap transaction, and calling wallet_transfer with encoded calldata to broadcast the swap. It references specific crypto swap APIs (WOOFi, 1inch, 0x, Paraswap), cross-chain bridging, and detailed execution steps (tx construction, signing via wallet, broadcast, and logging). These are specific crypto financial execution functions (not generic browser/API tooling), so the skill grants direct financial execution authority.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 19, 2026, 07:08 AM
Issues
2