gate-exchange-spot

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the gate-cli binary and its installation script from the official vendor repository on GitHub (github.com/gate/gate-cli). These downloads are authenticated by the vendor and are essential for the skill's core functionality.
  • [COMMAND_EXECUTION]: Local shell commands are executed via the setup.sh script to facilitate the installation of the gate-cli tool. The agent uses this CLI tool to perform all subsequent market queries and trading operations.
  • [PRIVILEGE_ESCALATION]: The installation script setup.sh includes a fallback mechanism that may use sudo to install the binary to /usr/local/bin if the default user-level directory is not writable. This is standard behavior for CLI tool installers.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests market data, including ticker information and order books, which represents a potential attack surface for external data injection. However, the skill implements a strict 'Mandatory Confirmation Gate' for all state-changing operations (buy, sell, amend, cancel), requiring the agent to present an order draft and wait for an explicit user response before executing any write command, which effectively mitigates this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 09:04 AM