woofi-bot

Warn

Audited by Snyk on Mar 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly exposes DEX swap execution functionality: POST /v1/swap (and legacy /swap) generates blockchain-ready transaction data, returns tx_steps with contract addresses, calldata and value, indicates needs_approve, and includes signer_address/wallet-ready flow. It is specifically designed to build and enable on-chain token swaps (crypto signing/broadcast steps), not merely generic querying. This is a direct crypto/blockchain execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 30, 2026, 01:39 AM
Issues
1