blofin-copy-trading

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed for financial operations. It exposes authenticated copy-trading APIs and actions such as fund_transfer (moving USDT to/from the copy_trading account), get_asset_balances, and full trading operations for lead traders: Place Order, Close Position, Set Leverage, TP/SL management, and order history. These are concrete transaction- and trade-execution capabilities (moving funds and executing market/limit orders), not generic tooling. Therefore it grants direct financial execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 04:44 PM