hive-nft-research
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted metadata from external NFT APIs, which serves as an ingestion point for potential indirect prompt injection. It mitigates this by requiring the agent to use a structured report template and by keeping collection-level and token-level evidence separate. The primary capability involved is the
invoke_api_endpointtool. - [DATA_EXFILTRATION]: The skill requires network access to function, using the
nft_researchtoolset to retrieve real-time blockchain and marketplace data. These network operations are necessary for the skill's stated purpose and are performed through managed tool interfaces.
Audit Metadata