trader-explain
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill specifies executing a bash command
npx neural-trader --predict --signal "$SIGNAL_ID" --explain --jsonwhere$SIGNAL_IDis a user-controllable parameter passed as an argument. If the agent interpolates this parameter into a raw shell command without escaping or validation, it creates a potential command injection vulnerability surface. - [EXTERNAL_DOWNLOADS]: The instruction references running
npx neural-trader, which invokes the npm package executor. Executing an unpinned and unscoped package name vianpxcreates a risk of dynamic retrieval and execution of untrusted external code if the package is missing locally or targeted by a registry supply-chain attack. - [CREDENTIALS_UNSAFE]: The skill requires resolving a private signing key from
RUFLO_WITNESS_KEY_PATHorverification/witness-key.jsonto sign attribution artifacts. Instructing the agent to locate and process cryptographic private keys directly risks exposing sensitive credentials inside the LLM context windows or logs.
Audit Metadata