portfolio

Warn

Audited by Snyk on Feb 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed for financial portfolio management across prediction markets and futures exchanges and lists platform-specific credentials and private keys (e.g., HL_PRIVATE_KEY, BINANCE_FUTURES_KEY/SECRET, BYBIT_API_KEY/SECRET, MEXC_API_KEY/SECRET, POLY/KALSHI API keys). It also names crypto/wallet integration (Hyperliquid via wallet address + private key) and direct exchange futures integrations (Binance Futures, Bybit, MEXC). These are specific crypto/blockchain and exchange APIs/credentials that enable signing transactions and executing trades — not merely generic HTTP or browser automation. Therefore it provides direct financial execution capability (wallet signing and exchange/trading API access).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 20, 2026, 08:52 PM