llm-trading-agent-security

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a security reference for trading agents. It correctly identifies and provides mitigations for common risks such as prompt injection and transaction slippage.
  • [CREDENTIALS_UNSAFE]: The code snippets demonstrate fetching a private key from an environment variable ('TRADING_WALLET_PRIVATE_KEY'), which is a documented safe practice for secret management compared to hardcoding credentials.
  • [EXTERNAL_DOWNLOADS]: The skill mentions a well-known Ethereum RPC service (Flashbots) as a mechanism for MEV protection. This is presented as an architectural recommendation rather than a hidden or suspicious download.
  • [INDIRECT_PROMPT_INJECTION]: The documentation explicitly warns against the risks of ingesting untrusted external data (social feeds, token labels) into LLM prompts and provides a regex-based sanitization example to mitigate these risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — llm-trading-agent-security