autoboy
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill incorporates defensive instructions against indirect prompt injection by explicitly directing the agent to treat API response content as untrusted data rather than executable instructions.
- [SAFE]: Network communications are restricted to the official vendor domains (thefirm.biz and docs.thefirm.biz) using secure HTTPS protocols.
- [SAFE]: The documentation provides full transparency regarding the third-party custodial nature of the smart wallet and mandates user approval for every state-changing operation, such as funding, placing orders, and withdrawals.
- [SAFE]: Security best practices for authentication are maintained, with instructions to pass API keys only via standard Authorization headers and to avoid exposure through logs or conversation history.
Audit Metadata