gate-exchange-trading-copilot
Warn
Audited by Snyk on Apr 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). Yes — this skill is explicitly a trading/execution copilot for a crypto/CFD exchange. The SKILL.md lists numerous specific "Execution Operations (Write)" MCP tools (e.g., cex_spot_create_spot_order, cex_fx_create_fx_order, cex_margin_create_uni_loan, cex_unified_create_unified_loan, cex_alpha_place_alpha_order, cex_fc_create_fc_multi_currency_* etc.) and describes workflows to place/cancel/amend orders, borrow/repay margin, perform flash swaps and TradFi orders. It also requires an authenticated API key and scopes for spot, futures, margin, flash swap, Alpha, TradFi and unified loans. Those are concrete APIs that perform market orders, swaps, borrowing/repayment and other financial actions — therefore this skill grants Direct Financial Execution Authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata