hyperliquid-advanced

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface area for indirect injection as it processes data from user requests and 'tickets' to execute financial actions.
  • Ingestion points: External instructions derived from user asks and ticketing systems mentioned in SKILL.md.
  • Boundary markers: Operational boundaries are defined by requirements for 'Execution Trader' oversight and the use of 'approved tickets' for all write actions.
  • Capability inventory: Trading capabilities include order placement, agent key approval, and the exchange's dead-man's switch functionality.
  • Sanitization: The skill maintains a strict safety policy by explicitly listing actions 'Deliberately not on this desk' (e.g., usdSend, withdraw3, vaultTransfer) to prevent the agent from performing unauthorized fund movements.
  • [SAFE]: No malicious code patterns, hardcoded credentials, or obfuscated content were detected in the skill instructions or provided code snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 09:33 AM
Security Audit — agent-trust-hub — hyperliquid-advanced