gate-exchange-autoinvest
Warn
Audited by Snyk on Apr 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed to perform cryptocurrency investment operations on Gate Exchange. It defines and maps specific write tools/commands that execute financial actions: e.g.
gate-cli cex earn auto-invest create,... update,... stop, and... add-position(the latter triggers an immediate purchase). It also includes balance checks (gate-cli cex spot account get) and requires API credentials (GATE_API_KEY/GATE_API_SECRET). These are not generic utilities — they are explicit, named commands whose primary purpose is to move funds/place purchases on an exchange (auto-invest/DCA). Therefore this skill grants direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata