find-next-crypto-idea

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes bash commands for telemetry management and logging within the ~/.superstack/ directory.\n- [DATA_EXFILTRATION]: The skill transmits platform and session information to a remote endpoint via curl. This telemetry is only active if the user opts in during the skill's initial setup.\n- [EXTERNAL_DOWNLOADS]: The skill recommends installing and using the bird.fast package from NPM for data collection from social media platforms.\n- [PROMPT_INJECTION]: The skill processes untrusted data from the web (X, GitHub, blogs) which presents an indirect prompt injection surface.\n
  • Ingestion points: Research output from live_research.py and data fetched from the Helius blog.\n
  • Boundary markers: None identified in the instructions to separate external data from agent commands.\n
  • Capability inventory: Access to curl, bash, and python3 for script execution.\n
  • Sanitization: The use of textContent in the HTML report generator provides mitigation against cross-site scripting (XSS) in generated reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 11:05 AM
Security Audit — agent-trust-hub — find-next-crypto-idea