Caveat verdict
nautilus-trader
Requires a blockchain wallet private key (HYPERLIQUID_PK) to execute real financial transactions on a live mainnet exchange; elevated credential access for real financial transactions.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (7)
Unicode homoglyph detected — uses lookalike characters to evade pattern matching
references/backtesting.md · prose
Possible hardcoded credential
references/other.md · code · password="your_password
Uses spawn() — can execute external programs
references/other.md · code · spawn(
Python os.getenv — reads environment variable
SKILL.md · code · os.getenv(
Opens WebSocket connection
references/other.md · code · WebSocket
Python urllib.request — network access
references/getting_started.md · code · urllib.request
References sudo — requests elevated privileges
references/other.md · prose · downgraded · sudo
Permissions & capabilities
No declared permissions — minimal attack surface.
package_installcredential_access Is this flag fair?
Thanks — recorded.