injective-rfq-integrations
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of documentation and architectural references. No executable scripts, binaries, or automated command sequences are included.
- [EXTERNAL_DOWNLOADS]: The documentation references official Injective infrastructure, including WebSocket and API endpoints (
rfq.ws.injective.network,rfq.gateway.grpc-web.injective.network) and block explorers (tcx.inj.so). These resources are consistent with the vendor 'injectiveLabs'. - [DATA_EXFILTRATION]: The instructions include clear security warnings against storing user wallet private keys and emphasize the use of scoped AuthZ grants to minimize risk when using local ephemeral signing keys.
- [INDIRECT_PROMPT_INJECTION]: The skill describes a flow that ingests quotes from external Market Makers via the TakerStream. It includes mandatory validation checklists—such as signature verification, price guardrails, and metadata matching—to ensure the integrity of the data processed by the agent.
Audit Metadata