trade

Warn

Audited by Snyk on Apr 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill repeatedly requires running "npx starkfi@latest" (which fetches and executes code from the npm registry at runtime), so external code is executed as a required dependency.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed to perform on-chain token swaps on Starknet. It provides concrete commands and parameters to execute trades (npx starkfi@latest trade ...), select providers, set slippage, simulate or broadcast transactions, and verify transaction status. It references gas/payment via a Paymaster, requires balances, and links to related swap/batch/multi-swap operations. These are direct crypto transaction capabilities (wallet/transaction execution), not generic tooling.

Issues (2)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 28, 2026, 11:52 AM
Issues
2