venice-errors

Warn

Audited by Snyk on Apr 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly describes an x402 "top-up" payment flow for USDC including: supportedTokens/supportedChains, receiverWallet/tokenAddress/network, and step-by-step instructions to "Sign a USDC transfer authorization using the x402 SDK (createPaymentHeader)" and then POST with the signed X-402-Payment header. It also references /crypto/rpc/* and idempotency for state-mutating (billable) calls. These are specific crypto payment/signing operations (wallet signing + submitting on-chain payment headers), not generic tooling, so it grants direct financial execution capability.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 23, 2026, 08:02 PM
Issues
1