skills/bankrbot/skills/signals/Gen Agent Trust Hub

signals

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests signal data and provider metadata from an external API, which represents an entry point for untrusted data into the agent's context.
  • Ingestion points: The skill fetches active signals and leaderboard data from https://bankrsignals.com/api/feed and https://bankrsignals.com/api/leaderboard as described in SKILL.md and HEARTBEAT.md.
  • Boundary markers: There are no specific instructions or delimiters provided to ensure the agent ignores directives that might be present in untrusted fields such as trade reasoning or provider names.
  • Capability inventory: The skill enables wallet signing and publishing trades; agents utilizing this skill may also have execution capabilities for copy-trading on DEXs.
  • Sanitization: No sanitization process is described for the external content before it is processed by the agent's reasoning engine.
  • [DYNAMIC_EXECUTION]: The skill uses local dynamic script execution to handle data processing and cryptographic signatures.
  • Evidence: The scripts/publish-signal.sh script executes a Node.js one-liner via node -e to sign EIP-191 messages using the viem library.
  • Evidence: The HEARTBEAT.md file suggests using python3 -c for parsing and filtering JSON data from the API response.
  • [COMMAND_EXECUTION]: The skill makes standard use of curl for API interaction and mkdir/cat for managing local configuration and state files within the ~/.clawdbot/skills/bankr/ directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — signals