crypto-algo-trader
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches a pre-trained time-series foundation model from Hugging Face during the initialization of the
ChronosPredictorclass inscripts/kronos_predict.py. - Evidence: The skill uses
ChronosPipeline.from_pretrained("amazon/chronos-tiny", ...)to download a model from Amazon's official repository. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection through its sentiment analysis component.
- Ingestion points: In
scripts/sentiment.py, the functionsanalyze_textandanalyze_multipleingest external strings (news headlines, tweets, and Reddit posts as described inSKILL.md) for processing. - Boundary markers: No specific delimiters or "ignore instructions" markers are present in the provided scripts to handle potential malicious instructions embedded in the external text.
- Capability inventory: The skill is designed for signal generation and backtesting. It lacks dangerous capabilities such as arbitrary shell command execution, file-writing to sensitive paths, or administrative privilege acquisition.
- Sanitization: The input text is passed directly to rule-based and pattern-based NLP libraries (
vaderSentimentandtextblob) without pre-processing or sanitization to strip potential prompt-based attacks.
Audit Metadata