market-intel

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill is subject to an indirect prompt injection surface as it ingests data from external sources like news feeds and decentralized exchange market listings. However, the risk is mitigated by the skill's primary purpose and the use of structured output templates.\n
  • Ingestion points: news_feed, tradfi_news, and dex_market tool calls across SKILL.md and references/defi-guide.md.\n
  • Boundary markers: Employs explicit output templates defined in references/output-templates.md to structure responses.\n
  • Capability inventory: Tool access is restricted to analytical and market data retrieval; no tools for command execution or sensitive file system access are provided.\n
  • Sanitization: Data is processed as-is, but the agent is instructed to add human-readable disclosures (e.g., regarding DEX promotions).\n- [EXTERNAL_DOWNLOADS]: A reference to an external MCP server (datahub.noxiaohao.com) is present in a code comment in SKILL.md. This is documented as a neutral reference to infrastructure and does not involve the execution of unverified remote scripts or packages.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 09:08 AM
Security Audit — agent-trust-hub — market-intel