gate-exchange-simpleearn
Warn
Audited by Snyk on Apr 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly includes authenticated "Execution Operations (Write)" MCP tools that create or modify financial orders on a crypto exchange (e.g., cex_earn_create_uni_lend, cex_earn_create_earn_fixed_term_lend, cex_earn_create_earn_fixed_term_pre_redeem, cex_earn_change_uni_lend). It requires an API key with Earn:Write permission and the routing rules describe collecting currency/amount/order_id and calling those write APIs to subscribe (lend), redeem, early-redeem, or change lend settings. These are specific, purpose-built financial actions on a crypto exchange (moving or controlling user funds), so this is direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata