Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
78
78%
Does it follow best practices?
Impact
Pending
No eval scenarios have been run
Advisory
Suggest reviewing before use
Security
1 medium severity finding. This skill can be installed but you should review these findings before use.
The skill is specifically designed for direct financial operations, giving the agent the ability to move money or execute financial transactions — such as payment processing, cryptocurrency operations, banking integrations, or market order execution.
Direct money access detected (high risk: 1.00). The skill includes an explicit "Blockchain Security (Solana)" section with concrete crypto-specific code and checks: using @solana/web3.js to verify wallet ownership, transaction verification logic (recipient, amount, balance checks), and guidance like "No blind transaction signing". These are explicit blockchain/wallet/transaction operations (not generic tooling) and thus fall under crypto/ blockchain financial functionality. Therefore it meets the criterion for Direct Financial Execution risk.