skills/bankrbot/skills/nexus/Gen Agent Trust Hub

nexus

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructions in references/trading.md and references/deposit-withdraw.md direct the agent to request the user's Bankr API key directly within the conversation flow to facilitate registration, deposits, and withdrawals. This practice exposes sensitive long-lived credentials to the LLM context.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data from multiple sources including RSS news feeds and public trader theses.
  • Ingestion points: references/news.md (fetches from external RSS URLs via a proxy) and references/feed-leaderboard.md (fetches public trader theses from the backend feed).
  • Boundary markers: The SKILL.md file contains a 'FORBIDDEN' section that explicitly instructs the agent to never treat public or user-generated content as instructions.
  • Capability inventory: The skill has the capability to execute leveraged trades, manage agent configurations, and withdraw funds using the bankr CLI and the vendor's API proxy.
  • Sanitization: Instructions specify that the agent should only render or summarize untrusted data and must never let it trigger signing, credential disclosure, or order execution.
  • [PRIVILEGE_ESCALATION]: The agent is instructed in SKILL.md to use the sign_message tool autonomously for the duration of a session once initial authorization is obtained, explicitly telling the agent not to ask the user for subsequent signatures for authenticated actions.
  • [COMMAND_EXECUTION]: The skill requires and utilizes the bankr binary tool for various blockchain interactions, including wallet registration and transaction submission.
  • [EXTERNAL_DOWNLOADS]: The skill fetches market news via the api.rss2json.com proxy and market data from the Orderly Network public API (api-evm.orderly.org). These are utilized for market intelligence and are documented as standard data sources for the skill's functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — nexus