hyperliquid-leaderboard-analytics
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill utilizes established and reputable Python libraries including textual, rich, and httpx for its terminal interface and network communication, following standard development practices for CLI tools.\n- [EXTERNAL_DOWNLOADS]: The skill's documentation provides installation instructions for cloning a GitHub repository. The source is clearly identified and the installation is a manual process initiated by the user, which is transparent and standard for open-source utilities.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the public Hyperliquid API, which represents a surface for processing external content.\n
- Ingestion points: External data is retrieved via the
HyperliquidAPIClientfrom theapi.hyperliquid.xyzendpoint.\n - Boundary markers: The provided snippets do not show specific delimiters or instructions for the agent to treat API data as untrusted.\n
- Capability inventory: The skill has the ability to write to the local filesystem through its
DataExporter(CSV, JSON, and Markdown) and perform network GET requests.\n - Sanitization: No specific input validation or sanitization logic is displayed in the provided usage patterns, though the data is primarily used for visualization and quantitative metrics.
Audit Metadata