upbit-manual-trading
Warn
Audited by Snyk on Mar 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). Yes. The skill is explicitly designed to execute cryptocurrency trades via the Upbit API. It exposes commands to place buys and sells, view balances and prices, and instructs storing UPBIT_ACCESS_KEY and UPBIT_SECRET_KEY environment variables so the agent can call an upbit_trading tool. The prompt describes REST API trading (market orders), examples of successful buy/sell transactions, and safety controls (confirmation thresholds, daily limits), which indicate the agent has direct authority to move funds on a crypto exchange. This meets the "Direct Financial Execution" criteria for crypto/blockchain APIs.
Audit Metadata