skopos
Warn
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill documentation and setup instructions suggest running
npx skopos-mcp@0.1.0to activate its MCP server. Thenpxutility downloads and executes packages from the npm registry at runtime, which is a potential vector for remote code execution. The skill correctly recommends pinning the version and reviewing the code, but the execution of remote packages remains a security consideration. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and display data from an external API (
tryskopos.xyz), which represents a surface for indirect prompt injection attacks. - Ingestion points: Data is ingested via
POST https://www.tryskopos.xyz/api/chatand several x402 JSON endpoints inSKILL.md. - Boundary markers: The
SKILL.mdfile contains strong directives for the agent to treat API responses as untrusted data, relay them verbatim, and ignore any instructions or links embedded within the text content. - Capability inventory: The skill allows the agent to relay text, present signing links for external execution, and perform x402 payments (USDC on Base).
- Sanitization: Documentation specifies that the server-side logic attempts to strip control and zero-width characters from emitted strings to prevent basic injection techniques.
- [EXTERNAL_DOWNLOADS]: The use of
npxinvolves downloading code from the npm registry. The skill also providescurlexamples that fetch data and documentation (such asllms.txtandopenapi.json) from thetryskopos.xyzdomain. - [COMMAND_EXECUTION]: The
catalog.jsonandSKILL.mdfiles containcurlcommands meant to be run to interact with the service's API endpoints for market data and intelligence. - [DATA_EXFILTRATION]: The skill performs network operations to
www.tryskopos.xyzto send user messages, conversation IDs (anonId), and potentially wallet information. While these are necessary for the skill's function, they constitute a transfer of data to an external service. The safety section advises confirming with the user before sharing sensitive financial information like transaction history or wallet addresses.
Audit Metadata