next-best-action
Warn
Audited by Snyk on Mar 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed for financial advisory operations and describes end-to-end integration with portfolio and trading systems. It repeatedly references execution workflows that pre-populate trades, "open the rebalancing tool with the client's accounts pre-loaded," generate "pre-generated trade proposals," and "submit the trades through the order management system" with tax-lot selection and executed trades logged. It also relies on custodial transaction feeds, margin-call handling, and other custody/trading events. Those are specific, non-generic capabilities to place market orders / execute asset trades (i.e., move financial assets), so it meets the "Direct Financial Execution" criterion.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata