social-intelligence
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
agentcashpackage globally (npm install -g agentcash) and utilizesnpx agentcash@latestfor executing commands. This practice downloads and runs code from the npm registry without version pinning, which can introduce supply chain risks if the package is compromised. - [COMMAND_EXECUTION]: The skill's primary workflows rely on shell-based execution of the
agentcashCLI tool to interact with APIs, check balances, and discover endpoints. This creates a dependency on an external binary that executes within the agent's environment. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and summarize untrusted data from Reddit posts and comments.
- Ingestion points: Data is ingested from
https://stableenrich.dev/api/reddit/searchandhttps://stableenrich.dev/api/reddit/post-commentsinSKILL.md. - Boundary markers: The instructions do not define explicit boundary markers or provide instructions for the agent to ignore potentially malicious embedded commands in the fetched content.
- Capability inventory: The agent has the ability to execute network requests and expend wallet funds via the
agentcashCLI tool. - Sanitization: There are no documented steps for sanitizing or filtering the retrieved Reddit content before it is processed by the model for sentiment analysis.
Audit Metadata