ethereum-app-builder

Warn

Audited by Snyk on Feb 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).


MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).


MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly for building and deploying Ethereum dApps ("build something onchain", "deploy a smart contract", "Scaffold full-stack Ethereum dApps using create-eth (Scaffold-ETH 2)"). Deploying contracts and operating onchain requires signing transactions and interacting with wallets/blockchain RPCs, so this is a tool specifically targeted at crypto/blockchain operations rather than a generic utility. Under the rule that crypto/blockchain (wallets, signing, on-chain transactions) are direct financial execution capabilities, this skill meets the criteria.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 20, 2026, 09:21 AM