aeon-defi-overview

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external DeFi market APIs to generate regime verdicts and yield sustainability reports, creating a potential vector for indirect prompt injection.
  • Ingestion points: Data is retrieved from external services including DefiLlama (api.llama.fi), GeckoTerminal, and various perpetual swap aggregators.
  • Boundary markers: The skill instructions lack explicit boundary markers or directives to ignore potential natural language instructions embedded within the fetched API data.
  • Capability inventory: The skill's primary capabilities are analytical, focusing on reporting, regime classification, and yield decomposition.
  • Sanitization: No specific evidence of data sanitization, filtering, or validation is present in the skill definition to mitigate malicious payloads in API responses.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external public data sources to function.
  • The skill is configured to fetch real-time market data from DefiLlama, GeckoTerminal, and perp aggregators to compute TVL changes, volume, and funding rates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:44 AM
Security Audit — agent-trust-hub — aeon-defi-overview