ton-bug-triage

Warn

Audited by Snyk on Mar 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly includes tools and scripts to build, sign, and send blockchain transactions on a TON network: e.g., scripts/wallet_send.py ("Build and optionally send a wallet-signed message" with --init-boc/--body-boc), scripts/send_boc.py ("Send a prebuilt serialized external message BoC"), run_liteclient.py, and other helpers for deploying StateInit and triggering contract messages. These are specific crypto/blockchain operations (wallet signing and sending transactions), not generic-purpose tooling, and therefore constitute direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 9, 2026, 05:43 PM