skills/bankrbot/skills/aero-stock-lp/Gen Agent Trust Hub

aero-stock-lp

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external sources that could theoretically contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The agent fetches market data from the GeckoTerminal API (api.geckoterminal.com) and price data from the Coinbase API (api.exchange.coinbase.com). It also reads blockchain state (position data, pool prices, gauge reward rates) via scripts/lib/chain.mjs and scripts/positions.mjs.
  • Boundary markers: The skill body in SKILL.md provides strict instructions for interpreting script outputs (JSON objects with defined fields) and requires the model to relay script reports nearly verbatim. However, it lacks explicit boundary markers or "ignore embedded instructions" warnings when interpolating this external data into its reasoning process.
  • Capability inventory: The skill is capable of proposing blockchain transactions via submit_raw_transaction, managing a local state file at ~/.aero-stock-lp/state.json, and executing bundled Node.js scripts to perform complex calculations and chain reads.
  • Sanitization: The bundled scripts perform deterministic validation and math (e.g., priceFromSqrtX96, inRange checks, and entry gates in entry.mjs) before presenting data to the agent, which serves as a significant layer of sanitization against raw data manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:47 AM
Security Audit — agent-trust-hub — aero-stock-lp