ave-wallet-suite

Warn

Audited by Snyk on Mar 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a wallet/trading router for crypto operations. It routes to sub-skills that perform self-custody signing and proxy-wallet execution, includes commands and workflows to create wallets, build and sign transactions, submit swaps/market-orders, monitor order status, and return tx hashes/order IDs. Examples: "Self-custody trade, unsigned tx build, local signing, mnemonic/private-key flows", "Proxy wallet, order management, bot-managed execution", scripts like "python scripts/ave_trade_rest.py market-order" and "swap-evm ... --auto-slippage", and fields to return (tx hash, proxy order ID, requestTxId). These are specific tools/functions to execute cryptocurrency trades and submit on-chain transactions, i.e., direct financial execution.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 18, 2026, 06:13 AM
Issues
1