cobra-strategy

Warn

Audited by Snyk on Mar 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is an automated trading strategy (COBRA) that explicitly defines entry logic, conviction-scaled position sizing (percent of account), DSL high-water trailing/stop-loss behavior, cron jobs for scanning and DSL execution, and notifications for "Position OPENED or CLOSED." It requires creating DSL state files and running a DSL engine to lock profit tiers and trigger exits. Although it doesn't name a specific broker API, its primary and explicit purpose is to open, size, manage, and close market positions — i.e., move money. This meets the "market orders / buying/selling assets" criterion for Direct Financial Execution.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 12, 2026, 06:26 PM
Issues
1