find-xemm-opps

Warn

Audited by Snyk on Mar 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).


MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a crypto trading utility: it finds cross-exchange market-making (XEMM) opportunities, references maker/taker hedging, mid-price gaps, and requires Hummingbot API plus "exchange connectors configured with API keys" (trading exchange integrations). Although the shown script appears to only analyze order books, its primary and explicit purpose is trading/hedging across exchanges (financial asset execution), and it depends on an API and exchange connectors that are used to place market orders. This meets the criterion for crypto/market-order financial capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 1, 2026, 09:56 AM