tiger-strategy
Warn
Audited by Snyk on Mar 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a trading system integrated with Senpi MCP and mcporter and contains direct market-execution APIs and commands. It defines and uses create_position, close_position, edit_position, cancel_order, and explicit order formats (orders array with coin, direction, leverage, marginAmount, orderType). It also includes funding commands (strategy_top_up / "Fund the wallet") and mcporter calls to close positions. These are specific, purpose-built financial execution primitives (opening/resizing/closing market positions and funding wallets), not generic tooling. Therefore it grants Direct Financial Execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata