Caveat verdict

bybit-trading-skill

45
🟠 Risky
Significant risk patterns flagged — automated deep scan, not behavioral proof.

Executes real financial trades on Bybit using user API credentials with explicit mainnet support — while it includes safety guardrails (testnet default, confirmation required, no withdraw permission), real-money trading via AI agent carries inherent risk beyond typical tool use.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

25
security
90
transparency
90
maintenance

Findings (5)

Pattern match critical

Possible hardcoded credential

SKILL.md · code · API_KEY="your_api_key

Pattern match high

Accesses shell history/config

SKILL.md · code · ~/.zshrc

Pattern match high

Accesses OpenClaw config/secrets directly

SKILL.md · code · ~/.openclaw/.env

Pattern match low

Opens WebSocket connection

SKILL.md · prose · downgraded · websocket

Pattern match low

References webhook/callback URL

modules/fiat.md · prose · downgraded · webhookUrl

Permissions & capabilities

Requires 2 environment variables. (2 sensitive: BYBIT_API_KEY, BYBIT_API_SECRET).

network_incredential_access

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API