openfin-pons

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes metadata from external blockchain and market data sources that could be influenced by third parties.
  • Ingestion points: Data retrieved from GET /agent/pons/tokens and GET /agent/pons/quote-assets (such as token names, tickers, and social media links) originates from public blockchain registries and external APIs.
  • Boundary markers: The skill includes explicit instructions for the agent to resolve and confirm tickers against an approved list and mandates a final user confirmation ("Get explicit 'yes' before submitting") before any state-changing action.
  • Capability inventory: The skill's capabilities are limited to documented API actions; it does not contain code for shell execution, file system access, or local persistence.
  • Sanitization: Instructions require the agent to show the user a full execution plan including exact fees and resolved assets, preventing the agent from autonomously acting on potentially malicious external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 08:31 PM
Security Audit — agent-trust-hub — openfin-pons