Axon CLI — local non-custodial trading terminal for AI agents (Claude Code, Claude Desktop, Cursor, Codex, Cline, Continue, Windsurf, Hermes, OpenClaw). Boots the daemon + dashboard + MCP server. Trade Hyperliquid perps, Uniswap V3 spot, Aave V3 lending,
- capability exposureinferred+35
- tool safetyinferred+12
- trust mitigatorsmixed−3
inferredmixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 10m ago · see ecosystem CVEs →
No known CVEs for this server.
- highdangerous code
credential logged in 1 file(s)
analyzed v1.15.1 · analyzer v18 · 10h ago
danger signals2
- suspicious endpointapi.telegram.orgpackage/dist/index.js:6540
const url = `https://api.telegram.org/bot${this.cfg.botToken}/sendMessage`; - credential in logscredential in logpackage/dist/index.js:19345
console.error(pc5.red(`Password must be at least ${MIN_PASSWORD_LEN} characters.`));
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of tytaninc7.