aero-stock-lp
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external sources that could theoretically contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The agent fetches market data from the GeckoTerminal API (
api.geckoterminal.com) and price data from the Coinbase API (api.exchange.coinbase.com). It also reads blockchain state (position data, pool prices, gauge reward rates) viascripts/lib/chain.mjsandscripts/positions.mjs. - Boundary markers: The skill body in
SKILL.mdprovides strict instructions for interpreting script outputs (JSON objects with defined fields) and requires the model to relay script reports nearly verbatim. However, it lacks explicit boundary markers or "ignore embedded instructions" warnings when interpolating this external data into its reasoning process. - Capability inventory: The skill is capable of proposing blockchain transactions via
submit_raw_transaction, managing a local state file at~/.aero-stock-lp/state.json, and executing bundled Node.js scripts to perform complex calculations and chain reads. - Sanitization: The bundled scripts perform deterministic validation and math (e.g.,
priceFromSqrtX96,inRangechecks, and entry gates inentry.mjs) before presenting data to the agent, which serves as a significant layer of sanitization against raw data manipulation.
Audit Metadata