Caveat verdict
bitget-wallet
bitget-wallet-skill-disabled
Bitget wallet integration using a documented agent API at copenapi.bgwapi.io with mandatory pre-checks (balance and token risk) before any swap; credential access is for the user's own wallet operations only.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
credential_access
Findings (5)
Pipe to python — executes piped content as Python code
docs/commands.md · code · | python3
Accesses system credential store
docs/wallet-signing.md · code · keychain
Base64 encoding/decoding
docs/x402-payments.md · prose · downgraded · base64-encode
Opens WebSocket connection
README.md · prose · downgraded · WebSocket
Python os.environ.get — reads environment variable
scripts/x402_pay.py · prose · downgraded · os.environ.get(
Permissions & capabilities
No declared permissions — minimal attack surface.
credential_access Is this flag fair?
Thanks — recorded.