aeon-token-movers

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches market data and coin details from CoinGecko's public API endpoints (api.coingecko.com). This is standard behavior for the stated purpose of market scanning.
  • [COMMAND_EXECUTION]: The skill uses curl commands to interact with the CoinGecko API and retrieve token metrics such as price changes, market capitalization, and volume.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from an external source (CoinGecko API) that is then presented to the agent.
  • Ingestion points: Data is ingested from api.coingecko.com as defined in SKILL.md.
  • Boundary markers: None identified in the provided instructions to delimit the external content.
  • Capability inventory: Network operations via curl to retrieve JSON data.
  • Sanitization: No specific sanitization or validation of the API response content is described before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:44 AM
Security Audit — agent-trust-hub — aeon-token-movers