trading-futures

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a trading/futures integration built to execute real financial transactions. It requires exchange API keys and a private wallet key, exposes numerous concrete methods to place, modify, cancel, and batch market/limit orders (binance.placeOrder, bybit.placeOrder, mexc.placeOrder, hyperliquid.placeOrder, TWAP, placeBatchOrders, etc.), manage leverage/margin, perform transfers and withdrawals (hyperliquid.usdTransfer, withdraw, spotTransfer, mexc.withdraw semantics), and manage account balances, staking, and vault deposits/withdrawals. Chat commands also include direct trading actions (/futures long, /futures short, /futures close-all, /futures tp/sl). These are specific, not generic, financial execution capabilities (crypto exchange and wallet operations and market orders), so the skill grants direct financial execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 04:29 AM