frontend

Warn

Audited by Snyk on Mar 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly targets VeChain dApp development and names crypto-specific tooling and operations: it instructs use of @vechain/mcp-server for "on-chain data, transaction building, and live network queries", references vechain-core for "fee delegation, and multi-clause transactions", and requires documenting "signing, fee, or token-transfer implications." Those are specific blockchain transaction/signing capabilities (i.e., moving crypto), not generic browser or HTTP tools. This meets the "Crypto/Blockchain (Wallets, Swaps, Signing)" criterion for Direct Financial Execution.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 12, 2026, 10:31 AM
Issues
1