signals
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests signal data and provider metadata from an external API, which represents an entry point for untrusted data into the agent's context.
- Ingestion points: The skill fetches active signals and leaderboard data from
https://bankrsignals.com/api/feedandhttps://bankrsignals.com/api/leaderboardas described inSKILL.mdandHEARTBEAT.md. - Boundary markers: There are no specific instructions or delimiters provided to ensure the agent ignores directives that might be present in untrusted fields such as trade reasoning or provider names.
- Capability inventory: The skill enables wallet signing and publishing trades; agents utilizing this skill may also have execution capabilities for copy-trading on DEXs.
- Sanitization: No sanitization process is described for the external content before it is processed by the agent's reasoning engine.
- [DYNAMIC_EXECUTION]: The skill uses local dynamic script execution to handle data processing and cryptographic signatures.
- Evidence: The
scripts/publish-signal.shscript executes a Node.js one-liner vianode -eto sign EIP-191 messages using theviemlibrary. - Evidence: The
HEARTBEAT.mdfile suggests usingpython3 -cfor parsing and filtering JSON data from the API response. - [COMMAND_EXECUTION]: The skill makes standard use of
curlfor API interaction andmkdir/catfor managing local configuration and state files within the~/.clawdbot/skills/bankr/directory.
Audit Metadata