mcp-user

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill follows security best practices by explicitly instructing the agent not to ask for credentials and requiring human-in-the-loop confirmation for all financial transactions.- [INDIRECT_PROMPT_INJECTION]: The skill processes external market data and account status via tool outputs, which is a necessary vulnerability surface for its primary trading purpose. This risk is effectively mitigated by mandatory user review.
  • Ingestion points: Market and account data are ingested via market_get_ticker, market_get_instruments, account_get_balance, and account_get_config in SKILL.md.
  • Boundary markers: No specific boundary markers are defined for the tool outputs.
  • Capability inventory: The skill utilizes order placement tools including spot_place_order and swap_place_order as documented in SKILL.md.
  • Sanitization: The instructions require the agent to summarize order parameters and obtain explicit user confirmation before execution, providing a strong human safeguard against accidental or malicious tool misuse.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:02 AM
Security Audit — agent-trust-hub — mcp-user