skills/ruvnet/ruflo/trader-explain/Gen Agent Trust Hub

trader-explain

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill specifies executing a bash command npx neural-trader --predict --signal "$SIGNAL_ID" --explain --json where $SIGNAL_ID is a user-controllable parameter passed as an argument. If the agent interpolates this parameter into a raw shell command without escaping or validation, it creates a potential command injection vulnerability surface.
  • [EXTERNAL_DOWNLOADS]: The instruction references running npx neural-trader, which invokes the npm package executor. Executing an unpinned and unscoped package name via npx creates a risk of dynamic retrieval and execution of untrusted external code if the package is missing locally or targeted by a registry supply-chain attack.
  • [CREDENTIALS_UNSAFE]: The skill requires resolving a private signing key from RUFLO_WITNESS_KEY_PATH or verification/witness-key.json to sign attribution artifacts. Instructing the agent to locate and process cryptographic private keys directly risks exposing sensitive credentials inside the LLM context windows or logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — trader-explain