self-evolving-agent
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted social media data (KOL sentiment, influencer trends, and community chatter) to influence its economic hypotheses and automated decision-making.
- Ingestion points: Data enters the context via social intelligence endpoints like
https://x402.ottoai.services/kol-sentimentas described inSKILL.mdandreferences/catalogue-findings.md. - Boundary markers: The skill documentation does not define specific delimiters or instructions to ignore embedded commands within the fetched social data.
- Capability inventory: The agent possesses the capability to provision mailboxes, manage Circle wallets, and execute gated financial transactions using endpoints defined in
references/endpoints.md. - Sanitization: No explicit sanitization or filtering logic is provided for the external social signals.
- [EXTERNAL_DOWNLOADS]: The skill fetches data and manages operational identity through several remote services.
- Retrieves market context and sentiment analysis from
ottoai.servicesendpoints. - Manages operational email and retrieves OTPs for wallet authentication via
agentmail.to. - Performs infrastructure availability checks through
stabledomains.dev. - These domains represent infrastructure within the vendor's ecosystem.
Audit Metadata