tax-loss-harvesting

Warn

Audited by Snyk on Mar 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly and specifically designed for tax-loss harvesting, including generation of actionable trade lists and execution planning that specifies buy/sell actions (security, account, action (sell/buy), shares, lot IDs, replacement security, wash-sale windows). It repeatedly instructs selling securities and purchasing replacements (worked examples show "Sell XYZ Corp" and "buy Sector ETF") and coordinates trades across accounts. Although it doesn't name a particular broker API, its primary, explicit purpose is to identify and drive market orders (buying/selling assets) as part of the TLH workflow. That constitutes direct financial execution capability (market orders).

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 11, 2026, 03:43 PM
Issues
1