yield-optimization

Pass

Audited by Gen Agent Trust Hub on Apr 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the MoonPay CLI (@moonpay/cli) from the public npm registry. This is a vendor-provided tool used for wallet management and transaction signing.- [REMOTE_CODE_EXECUTION]: Uses npx clawhub@latest to install the agent skill, which involves fetching and executing code from a remote registry.- [EXTERNAL_DOWNLOADS]: Fetches additional shell scripts and configuration from the official StakeKit GitHub repository (github.com/stakekit/yield-agent.git).- [COMMAND_EXECUTION]: Requires execution of local shell scripts for yield discovery and transaction building. Instructions include granting execution permissions via chmod +x.- [CREDENTIALS_UNSAFE]: References the use of a YIELDS_API_KEY environment variable. The skill correctly recommends managing this via environment variables rather than hardcoding.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 23, 2026, 10:47 PM
Security Audit — agent-trust-hub — yield-optimization