ton-vulnerability-scanner

Warn

Audited by Snyk on Feb 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is focused on TON blockchain smart contracts and explicitly includes concrete blockchain/wallet operations and transaction APIs in examples and tests (e.g., @ton/sandbox Blockchain, blockchain.treasury, getWalletAddress, sendInternalMessage/sendTransfer, toNano, send_raw_message, Jetton wallet handling, forward TON amounts). Those are specific crypto/blockchain wallet and transfer functions—not generic tooling—so it exposes explicit capabilities to construct and send token/TON transactions. Therefore it constitutes Direct Financial Execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 10:25 PM