aeon-defi-monitor
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the skill core from the vendor's repository on GitHub.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external DeFi APIs (api.llama.fi and yields.llama.fi) and on-chain RPC providers. This data influences generated alerts and action payloads. If these external sources were compromised, they could potentially inject instructions into the agent's context. 1. Ingestion points: DeFi data from DefiLlama and RPC nodes. 2. Boundary markers: No explicit delimiters specified to isolate untrusted API data. 3. Capability inventory: The skill generates transaction payloads for the Bankr tool. 4. Sanitization: No documented filtering or validation of strings retrieved from external sources.
Audit Metadata