hyperliquid-reader

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses shell commands within SKILL.md for environment status checks at load time.
  • [EXTERNAL_DOWNLOADS]: The skill requires installing a CLI tool from npm and a plugin from a GitHub repository owned by the author.
  • [COMMAND_EXECUTION]: The skill performs shell execution to fetch market data from the Hyperliquid info API.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Hyperliquid public API, which is a vector for indirect prompt injection. 1. Ingestion points: Data from api.hyperliquid.xyz/info. 2. Boundary markers: The skill instructions lack explicit delimiters or instructions to ignore embedded prompts in API data. 3. Capability inventory: Command execution via opencli and network operations. 4. Sanitization: No sanitization is implemented for the external market data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 12:30 PM
Security Audit — agent-trust-hub — hyperliquid-reader