crypto-etl-analytics-core
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs users to clone a code repository from an external, unverified GitHub account (
Jad-srifi/crypto-etl-analytics-core). This represents a potential risk as the remote code is not from a known trusted vendor. - [COMMAND_EXECUTION]: The installation and setup instructions include shell commands for cloning repositories, installing packages via pip, and pipe-executing SQL scripts into a MySQL database instance.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from a MySQL database.
- Ingestion points: The
extract_candlesfunction inSKILL.mdreads data from thecrypto_1d_candlestable. - Boundary markers: The implementation uses parameterized SQL queries (
%s) to prevent SQL injection. - Capability inventory: The skill includes file system write capabilities via the
matplotlib.pyplot.savefigfunction. - Sanitization: Standard database parameterization is applied, but there are no explicit delimiters or sanitization steps for the processed data if it were to be passed to a downstream LLM context.
Audit Metadata