trading-on-uniswap

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches pair and price information from the public DexScreener API. Because this data is from an external, untrusted source, it could potentially be manipulated by an attacker to influence the agent's trading logic or parameters.
  • Ingestion points: Data is fetched via curl from api.dexscreener.com and processed using jq in the SKILL.md file.
  • Boundary markers: The instructions do not specify any delimiters or safety warnings for the agent when interpreting the API output.
  • Capability inventory: The skill has powerful capabilities, including executing on-chain transactions and token approvals via the agw CLI.
  • Sanitization: The skill uses jq to parse and filter the JSON response, which provides basic structural validation but does not prevent the interpretation of malicious content within the fields.
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to api.dexscreener.com, a well-known third-party service, to retrieve live market data.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands, specifically curl for network operations, jq for data processing, and the agw CLI for interacting with the Abstract blockchain.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:30 AM
Security Audit — agent-trust-hub — trading-on-uniswap