NYC

backtesting-frameworks

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly a trading/backtesting framework (not a generic tool) and defines market-order primitives and execution logic. It includes Order and OrderType (MARKET/BUY/SELL), an ExecutionModel with an execute(order, ...) method (SimpleExecutionModel.execute returns Fill for MARKET orders), and Portfolio.process_fill that updates cash/positions based on fills. Those are explicit market-order / buy-sell transaction primitives (even if simulated) and therefore constitute direct financial execution capability per the "market orders" criterion.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 10:08 PM