crypto-com-app

Warn

Audited by Snyk on Mar 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a crypto trading integration for Crypto.com with built-in, specific commands to execute financial actions. It requires API keys/secret and signed requests, and provides a two-step trade flow (quote → confirm) with concrete commands to perform purchases, sales, exchanges and to confirm orders (e.g., npx tsx $SKILL_DIR/scripts/trade.ts quote ... and ... confirm <quotation-id>). It also supports revoking API keys (kill switch), querying balances, trading limits, and "sell all" workflows. This is not a generic tool — it is specifically designed to move cryptocurrency funds and perform market orders/swaps, so it meets the Direct Financial Execution criteria.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 07:46 AM
Issues
1