ltp-rapidx-trading

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No malicious patterns, unauthorized exfiltration, or persistence mechanisms were identified in the skill instructions or reference files.
  • [COMMAND_EXECUTION]: The skill utilizes the rapidx CLI tool and MCP tools for trading operations. This is the primary function of the skill and is governed by robust safety rules requiring explicit user confirmation and preview validation for every transaction.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of @liquiditytech/rapidx-cli from the official npm registry. This is a trusted resource belonging to the skill's author (LiquidityTech) and is necessary for the skill's operation.
  • [CREDENTIALS_UNSAFE]: The instructions include best practices for managing LTP_ACCESS_KEY and LTP_SECRET_KEY, explicitly warning against echoing secrets and recommending the use of the agent host's secure secret management systems.
  • [PROMPT_INJECTION]: Static detections regarding 'concealment' were reviewed and found to be false positives; the skill's instructions actually mandate transparency by forbidding the silent replacement of market orders.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 08:05 AM
Security Audit — agent-trust-hub — ltp-rapidx-trading