market-scanner

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill does not contain any malicious commands, shell scripts, or executable code. The YAML frontmatter and markdown content are limited to descriptive process documentation.
  • [NO_CODE]: No scripts (.py, .js, .sh) or tool configurations were found. The skill is purely informational.
  • [PROMPT_INJECTION]: The workflow describes ingesting untrusted data from external sources like Twitter/X, HN, and blogs (Category 8: Indirect Prompt Injection surface). While no code is present to execute these scans, the process involves processing data that could contain malicious instructions.
  • Ingestion points: SKILL.md (Step 1: Scan Sources)
  • Boundary markers: Absent from the documentation.
  • Capability inventory: None; no tools or scripts are defined in this skill.
  • Sanitization: No sanitization or validation methods are described.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:07 PM
Security Audit — agent-trust-hub — market-scanner