market-structure-analyzer
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
subprocess.run()within thefetch_market_data.pyscript to execute theokxandonchainosCLI tools. These commands are essential for retrieving real-time derivatives and smart money signals. The implementation uses list-based arguments rather than shell strings, which is a secure practice for preventing command injection. - [EXTERNAL_DOWNLOADS]: The agent retrieves market indicators and macro sentiment data from well-known technology services and financial data providers, including OKX, CoinMetrics, CoinGecko, Alternative.me, and DefiLlama. These interactions are documented and are standard for market analysis tools.
- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests data from multiple external APIs. However, the
SKILL.mdfile contains specific 'Security & Data Trust' instructions (referenced as M07 and M08) that direct the agent to treat API outputs as untrusted and read-only, preventing their raw inclusion in sensitive contexts. - [DYNAMIC_EXECUTION]: A dynamic import (
__import__) is used in the data fetcher script for the standard Pythondatetimelibrary. This is used for calculating MVRV history windows and does not pose a security risk as it does not involve loading untrusted modules or executing remote code.
Audit Metadata