tiger
Warn
Audited by Snyk on Jun 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly a trading/broker integration (tigeropen SDK) and includes commands to place and cancel market/limit orders (e.g., "place --symbol AAPL --side buy --qty 1 --type market", "cancel --order-id "). It requires account credentials and has a live-vs-paper guard (live placement requires --confirm-live). This is a specific API for executing market orders (buy/sell) — direct financial execution.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata