crypto-algo-trader

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches a pre-trained time-series foundation model from Hugging Face during the initialization of the ChronosPredictor class in scripts/kronos_predict.py.
  • Evidence: The skill uses ChronosPipeline.from_pretrained("amazon/chronos-tiny", ...) to download a model from Amazon's official repository.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection through its sentiment analysis component.
  • Ingestion points: In scripts/sentiment.py, the functions analyze_text and analyze_multiple ingest external strings (news headlines, tweets, and Reddit posts as described in SKILL.md) for processing.
  • Boundary markers: No specific delimiters or "ignore instructions" markers are present in the provided scripts to handle potential malicious instructions embedded in the external text.
  • Capability inventory: The skill is designed for signal generation and backtesting. It lacks dangerous capabilities such as arbitrary shell command execution, file-writing to sensitive paths, or administrative privilege acquisition.
  • Sanitization: The input text is passed directly to rule-based and pattern-based NLP libraries (vaderSentiment and textblob) without pre-processing or sanitization to strip potential prompt-based attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — crypto-algo-trader