aicoin-hyperliquid
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The file
lib/defaults.jsoncontains default API credentials that are explicitly documented as public free-tier keys provided by the vendor for standard functionality. - [EXTERNAL_DOWNLOADS]: The skill interacts with the AiCoin Open API at
open.aicoin.comfor market data retrieval, which is the intended purpose and targets a verified vendor domain. - [COMMAND_EXECUTION]: The skill uses Node.js scripts for its operations and includes instructions to the agent to avoid running commands like
envorprintenvthat could expose user secrets stored in the environment. - [PROMPT_INJECTION]: The skill provides clear constraints to the agent, such as prohibiting data fabrication and requiring the use of specific authenticated scripts instead of generic network utilities like
curlorwget.
Audit Metadata