rqalpha
Warn
Audited by Snyk on Apr 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a trading/backtesting framework with built-in order APIs. The prompt documents concrete order functions (order_shares, order_lots, order_value, order_percent, order_target_value, order_target_percent, cancel_order) and futures trade functions (buy_open, sell_open, buy_close, sell_close). It also notes real/live trading can be connected via rqalpha-mod-vnpy to broker gateways. These are specific market-order / trade-execution interfaces (i.e., sending transactions to buy/sell assets), so it grants direct financial execution capability.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata