crypto-trading-bots

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and reference files focus on best practices for crypto trading automation. No malicious patterns, prompt injections, or unauthorized data exfiltration techniques were detected.
  • [CREDENTIALS_UNSAFE]: The skill proactively addresses credential safety by including a validation rule that flags hardcoded private keys in TypeScript/JavaScript files and recommends using environment variables.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or suspicious package installation patterns were found. The code snippets use well-known, legitimate libraries (ethers and @flashbots/ethers-provider-bundle) for blockchain interaction.
  • [INDIRECT_PROMPT_INJECTION]: While the skill involves processing external data (token addresses and contract bytecode), it implements defensive checks (honeypot simulation, liquidity lock verification, and dangerous function selector checks) to mitigate risks associated with untrusted tokens.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:52 PM
Security Audit — agent-trust-hub — crypto-trading-bots