bald-eagle
Warn
Audited by Snyk on Mar 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a purpose-built autonomous trading agent for XYZ tokenized equities on Hyperliquid's xyz dex. It specifies trading actions and execution details (margin sizing, leverage, "entry" with asset/direction/leverage/marginPercent), DSL execution order types (e.g., phase1SlOrderType: "MARKET"), and operational instructions that the agent must "accept scanner signals and open positions". It even mandates bootstrap verification before trading and notification rules for position OPENED/CLOSED. These are direct, specific financial execution capabilities (placing market orders, managing margin/leverage) rather than generic tooling.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata