defi-trading-systems

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes logic for processing external blockchain data, such as transaction history and block metadata, which represents a potential injection surface if the data source is malicious.
  • Ingestion points: The detect_sandwich function in references/mev-protection.md processes transaction data retrieved from blockchain blocks.
  • Boundary markers: No explicit boundary markers or instructions to isolate untrusted blockchain data are present in the code snippets.
  • Capability inventory: The skill utilizes network capabilities via the web3 library and requests for interacting with RPC providers and industry-standard mempool relays.
  • Sanitization: The provided examples do not include sanitization or validation logic for external blockchain transaction fields.
  • [EXTERNAL_DOWNLOADS]: The skill uses standard industry libraries such as numpy for risk metrics and web3, eth-account, and requests for blockchain interactions. All external calls, including those to well-known service relays, are consistent with the documented purpose of designing trading systems.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — defi-trading-systems