1inch-market-data

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill facilitates access to cryptocurrency market data (prices, gas, charts) through the 1inch product_api tool. All operations are scoped to the vendor's official interface.
  • [PROMPT_INJECTION]: The skill ingests external data from the product_api, which constitutes a potential surface for indirect prompt injection. 1. Ingestion points: Market data returned from the product_api tool, as referenced in SKILL.md and references/RECIPES.md. 2. Boundary markers: The instructions do not define explicit delimiters or warnings for the agent to ignore instructions embedded in the API response. 3. Capability inventory: Uses the product_api tool for network requests, the search tool for discovery, and reads from the file://1inch-mcp/guides/api-index resource. 4. Sanitization: The skill does not specify any sanitization for the structured data returned by the API.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 05:48 PM
Security Audit — agent-trust-hub — 1inch-market-data