nexus
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructions in
references/trading.mdandreferences/deposit-withdraw.mddirect the agent to request the user's Bankr API key directly within the conversation flow to facilitate registration, deposits, and withdrawals. This practice exposes sensitive long-lived credentials to the LLM context. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data from multiple sources including RSS news feeds and public trader theses.
- Ingestion points:
references/news.md(fetches from external RSS URLs via a proxy) andreferences/feed-leaderboard.md(fetches public trader theses from the backend feed). - Boundary markers: The
SKILL.mdfile contains a 'FORBIDDEN' section that explicitly instructs the agent to never treat public or user-generated content as instructions. - Capability inventory: The skill has the capability to execute leveraged trades, manage agent configurations, and withdraw funds using the
bankrCLI and the vendor's API proxy. - Sanitization: Instructions specify that the agent should only render or summarize untrusted data and must never let it trigger signing, credential disclosure, or order execution.
- [PRIVILEGE_ESCALATION]: The agent is instructed in
SKILL.mdto use thesign_messagetool autonomously for the duration of a session once initial authorization is obtained, explicitly telling the agent not to ask the user for subsequent signatures for authenticated actions. - [COMMAND_EXECUTION]: The skill requires and utilizes the
bankrbinary tool for various blockchain interactions, including wallet registration and transaction submission. - [EXTERNAL_DOWNLOADS]: The skill fetches market news via the
api.rss2json.comproxy and market data from the Orderly Network public API (api-evm.orderly.org). These are utilized for market intelligence and are documented as standard data sources for the skill's functionality.
Audit Metadata