emblem-market-research
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions specify a dependency on the
@emblemvault/agentwalletglobal Node.js package. This is a vendor-provided CLI tool necessary for the skill's operation. - [COMMAND_EXECUTION]: The skill uses the
emblemaiCLI to perform research tasks. It also provides a shell script,scripts/market-scan.sh, which automates several CLI commands to generate market reports. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes market data from various third-party APIs (CoinGecko, Birdeye, CoinGlass, Nansen) which could theoretically contain malicious instructions embedded in token names or metadata.
- Ingestion points: Data enters the agent's context through tools like
getTrendingCoins,birdeyeTradeData, andnansen_smart_money_flowsdescribed in SKILL.md. - Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded content in the tool outputs.
- Capability inventory: The skill possesses shell command execution capabilities via the
emblemaiCLI. - Sanitization: There is no explicit sanitization logic within the skill; it relies on the agent platform's internal safeguards and the CLI tool's data handling.
Audit Metadata