openfin-pons
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes metadata from external blockchain and market data sources that could be influenced by third parties.
- Ingestion points: Data retrieved from
GET /agent/pons/tokensandGET /agent/pons/quote-assets(such as token names, tickers, and social media links) originates from public blockchain registries and external APIs. - Boundary markers: The skill includes explicit instructions for the agent to resolve and confirm tickers against an approved list and mandates a final user confirmation ("Get explicit 'yes' before submitting") before any state-changing action.
- Capability inventory: The skill's capabilities are limited to documented API actions; it does not contain code for shell execution, file system access, or local persistence.
- Sanitization: Instructions require the agent to show the user a full execution plan including exact fees and resolved assets, preventing the agent from autonomously acting on potentially malicious external data.
Audit Metadata