gate-exchange-crossex

Warn

Audited by Snyk on Apr 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).


MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed for trading and fund movement across crypto exchanges via the gate-cli. It lists authenticated, write-capable commands such as order create, order cancel, transfer create, convert create, position set-leverage and other execution operations, and requires API keys for authenticated calls. These are specific financial execution tools (market orders, cross-exchange transfers, flash converts) intended to move or change user funds/positions, so it grants Direct Financial Execution authority.

Issues (2)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 26, 2026, 03:51 PM
Issues
2