quotient
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands via binaries like curl, jq, and bankr to perform data retrieval and trade execution tasks. These operations are essential to its documented functionality.
- [DATA_EXFILTRATION]: The skill performs network operations to interact with vendor infrastructure at quotient-api-gateway.onrender.com and api.bankr.bot, as well as well-known prediction market venues including Polymarket and Hyperliquid. These operations are used for fetching intelligence and submitting trades.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data such as market questions, news article summaries, and social media posts fetched from external APIs. 1. Ingestion points: Untrusted content enters the agent's context through the Quotient API via the quotient.sh and signal-strategy.mjs scripts. 2. Boundary markers: The SKILL.md file contains explicit security guardrails instructing the agent to treat all fetched content as untrusted and not to execute instructions contained within it. 3. Capability inventory: The skill possesses the capability to execute shell commands and trigger financial transactions via the bankr CLI tool. 4. Sanitization: The skill mitigates risks by validating identifiers like market slugs against a strict regular expression in signal-strategy.mjs and using URL encoding for API parameters.
Audit Metadata