order-lifecycle
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly about order lifecycle management and FIX-based trading connectivity. It defines NewOrderSingle (MsgType=D) as the message used to "submit a new order to the venue," describes ExecutionReports, OrderCancelRequest and OrderCancelReplaceRequest, order types (market, limit, IOC, FOK, etc.), time-in-force, cancel/replace workflows, and FIX session/application behaviors. It also covers buying-power checks, position limits, venue routing, and building FIX connectivity to execute orders on exchanges/ECNs. These are concrete, purpose-built mechanisms for placing, amending, cancelling, and managing market orders (i.e., moving financial assets), not generic tooling. Therefore it grants direct financial execution capability.
Audit Metadata