5minbtc
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The script
5minbtc-news.pyexecutes local sub-scripts viasubprocess.runto gather news from Telegram channels. - Evidence: The script dynamically constructs paths to
telegram-treenews.pyandtelegram-cointelegraph.pywithin the skill'sscripts/directory and executes them using the Python interpreter. - [EXTERNAL_DOWNLOADS]: The skill fetches market data and news from several external domains to perform its analysis.
- Evidence: It makes network requests to
data-api.binance.visionfor K-line data,api.coinbase.comfor spot prices, and several news RSS feeds including CoinDesk and CoinTelegraph. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted news content from external websites, which could potentially contain malicious instructions targeting the AI agent.
- Ingestion points: News headlines and bodies are scraped from multiple third-party crypto news websites in
5minbtc-news.py. - Boundary markers: While data is structured in JSON, the agent's instructions in
SKILL.mdprompt for a "comprehensive analysis" of the content without specific guardrails against embedded instructions. - Capability inventory: The skill has access to terminal commands, web tools, and local script execution.
- Sanitization: No specialized sanitization is performed on the scraped news text before it is presented to the agent.
- [CREDENTIALS_UNSAFE]: The script
5minbtc-news.pyreads the user's shell configuration file to extract API keys. - Evidence: The function
load_env()in5minbtc-news.pyopens~/.bashrcand scans for lines starting withexportthat contain_API_KEYto populate the environment variables used by the tool.
Audit Metadata