trading-futures
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a trading/futures integration built to execute real financial transactions. It requires exchange API keys and a private wallet key, exposes numerous concrete methods to place, modify, cancel, and batch market/limit orders (binance.placeOrder, bybit.placeOrder, mexc.placeOrder, hyperliquid.placeOrder, TWAP, placeBatchOrders, etc.), manage leverage/margin, perform transfers and withdrawals (hyperliquid.usdTransfer, withdraw, spotTransfer, mexc.withdraw semantics), and manage account balances, staking, and vault deposits/withdrawals. Chat commands also include direct trading actions (/futures long, /futures short, /futures close-all, /futures tp/sl). These are specific, not generic, financial execution capabilities (crypto exchange and wallet operations and market orders), so the skill grants direct financial execution authority.
Audit Metadata