ave-trade-chain-wallet
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly and primarily designed to perform on-chain crypto financial operations. It provides APIs/CLI commands to get swap quotes, build unsigned EVM and Solana transactions, sign transactions with local private keys or mnemonics, submit pre-signed transactions, and perform one-step create+sign+send DEX swaps. Environment variables for private keys/mnemonics and explicit commands like swap-evm, swap-solana, send-evm-tx, send-solana-tx demonstrate direct ability to move funds on-chain. This matches the "Crypto/Blockchain (Wallets, Swaps, Signing)" category in the core rule, so it grants Direct Financial Execution Authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata