hyperliquid
Warn
Audited by Snyk on Feb 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a trading/investment integration for a crypto DEX. It exposes signed exchange endpoints (POST /exchange) that require EIP‑712 wallet signatures and provide concrete, specific financial actions: place order, cancel order, modify orders, TWAP orders, update leverage/isolate margin, usdClassTransfer (spot <-> perp transfers), and vault deposit/withdraw. These are direct transaction-executing APIs for moving funds and placing market orders on-chain, not generic utilities. Therefore it grants direct financial execution capability.
Audit Metadata