hunch-bazaar
Fail
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: CRITICALMETADATA_POISONINGEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The skill metadata and documentation direct users to websites identified as phishing risks by automated security analysis tools.
- Evidence:
bazaar.playhunch.xyz,www.playhunch.xyz, andhttps://bazaar.playhunch.xyzare flagged as malicious phishing domains by the URLite scanner. - [EXTERNAL_DOWNLOADS]: The skill instructions require the user to perform an external installation from a personal, unverified GitHub repository (
rajkaria/hunch-skills) rather than a trusted organization or vendor. - Evidence: Reference to
https://github.com/rajkaria/hunch-skills/tree/78803b097712d74657e2798e9fc0c68f6a3bd1c0/hunch-bazaarinSKILL.mdandcatalog.json. - [DATA_EXFILTRATION]: The skill facilitates the transfer of financial assets (USDC) to a centrally controlled settlement account instead of a decentralized escrow contract. Given the associated phishing alerts for the target domain, this model presents a high risk of asset loss.
- Evidence: The skill explicitly states: "Payments go to the pinned Hunch-controlled settlement account, not a rule-enforcing market escrow contract."
- [INDIRECT_PROMPT_INJECTION]: The skill allows the creation of markets based on arbitrary user input, creating a surface for prompt injection attacks that could influence agent behavior during market drafting or betting.
- Ingestion points: User-provided phrases for market creation in
SKILL.md(e.g., "make a market from a phrase"). - Boundary markers: Absent; there are no instructions to delimit or ignore embedded instructions within the market phrase.
- Capability inventory: The skill utilizes native
sign_dataand accesses permanent wallet files, as noted incatalog.json. - Sanitization: Absent; no validation, escaping, or filtering of the user-provided market descriptions is described.
Recommendations
- AI detected serious security threats
- Contains 3 malicious URL(s) - DO NOT USE
Audit Metadata