@1390/woofi-swap
Warn
Audited by Snyk on Apr 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a crypto swap API/aggregator (WOOFi) that quotes and builds/on-chain transaction data for token swaps across multiple EVM chains. The /v1/swap endpoint generates blockchain-ready tx_steps (including approval and swap transactions) intended to be signed and broadcast by a wallet, and the skill supports buying/selling any ERC‑20 or native token. This is a specific financial execution capability (crypto wallet transactions, swaps, signing), not a generic tool, so it grants direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata