account-intel

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function involves making structured API requests to established social media, search, and blockchain infrastructure providers (Alchemy, Brave, Exa) and vendor-owned services (SELAT-AI). These network operations are consistent with the skill's stated purpose of gathering entity footprint data.
  • [DATA_EXPOSURE]: The skill processes user-provided inputs such as handles, entity names, and EVM contract addresses. It does not attempt to access sensitive local files (e.g., SSH keys, AWS credentials), environment variables, or other private data.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform any remote code execution. It lacks patterns such as piping web content into shell interpreters (curl|bash) or downloading executable scripts from unknown sources.
  • [COMMAND_EXECUTION]: There are no instances of arbitrary or dangerous local command execution. The mentioned CLI operations (selat skill, selat-pay) are part of the intended deployment and validation workflow for the skill's specific ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: As a data aggregation tool, the skill ingests content from external web and social sources (X, YouTube, Brave News). While this constitutes an attack surface for indirect prompt injection, the risk is inherent to the profiling use case and is managed by the agent's internal processing logic rather than the skill's configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 07:34 PM
Security Audit — agent-trust-hub — account-intel