etoro
Pass
Audited by Gen Agent Trust Hub on Mar 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection vulnerability surface detected.
- Ingestion points: The skill retrieves data from eToro social feeds using the
/feeds/instrument/{marketId}and/feeds/user/{userId}endpoints described inSKILL.md. - Boundary markers: The skill lacks explicit boundary markers or instructions to the agent to disregard commands potentially embedded within the ingested social feed content.
- Capability inventory: The skill has high-impact capabilities, including placing market and limit orders via the
/trading/execution/endpoints defined inSKILL.md. - Sanitization: There is no evidence of sanitization or validation of the feed content before it is processed by the agent.
Audit Metadata