SunPerp Perpetual Futures Trading

Warn

Audited by Snyk on Apr 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed for trading and moving funds. It provides REST API scripts to place/cancel market and limit orders, set leverage, manage positions, and execute withdrawals on SunPerp (a TRON-based perpetual futures DEX). It requires API keys with Trade/Withdraw permissions and a TRON_PRIVATE_KEY for signing withdrawals, and includes commands like node scripts/order.js place ... and node scripts/wallet.js withdraw ... (full withdraw flow: apply → sign → confirm). Those are specific financial execution capabilities (crypto trading, wallet signing, and withdrawals), not generic tooling.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 10, 2026, 07:05 AM
Issues
1
Security Audit — snyk — SunPerp Perpetual Futures Trading