skills/bankrbot/skills/agenticbets/Gen Agent Trust Hub

agenticbets

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes market data from an external API (agenticbets.dev), which could theoretically contain malicious instructions designed to influence agent behavior.
  • Ingestion points: Data is ingested via GET requests in the fetch_markets function of scripts/agenticbets.py.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the market data as untrusted.
  • Capability inventory: The skill has the ability to submit blockchain transactions, approve token spending, and make network requests.
  • Sanitization: The script performs JSON parsing but does not sanitize the contents of the market fields before they are presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — agenticbets