cli-coingecko
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute
cgCLI commands to perform market analysis and data retrieval. It emphasizes non-interactive status checks and structured data output. - [REMOTE_CODE_EXECUTION]: The skill mentions updating the
cgutility using various methods, including scripts. To mitigate risk, the instructions require explicit user approval and the use of dry-run flags before any updates are applied. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the CoinGecko API, which is an external source. It reduces the surface for data-driven attacks by specifying JSON output formats and resolving ambiguous coin identifiers.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The documentation includes a safety directive to never expose API keys or private wallet information when interacting with market-data endpoints.
Audit Metadata