self-evolving-agent

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests untrusted social media data (KOL sentiment, influencer trends, and community chatter) to influence its economic hypotheses and automated decision-making.
  • Ingestion points: Data enters the context via social intelligence endpoints like https://x402.ottoai.services/kol-sentiment as described in SKILL.md and references/catalogue-findings.md.
  • Boundary markers: The skill documentation does not define specific delimiters or instructions to ignore embedded commands within the fetched social data.
  • Capability inventory: The agent possesses the capability to provision mailboxes, manage Circle wallets, and execute gated financial transactions using endpoints defined in references/endpoints.md.
  • Sanitization: No explicit sanitization or filtering logic is provided for the external social signals.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data and manages operational identity through several remote services.
  • Retrieves market context and sentiment analysis from ottoai.services endpoints.
  • Manages operational email and retrieves OTPs for wallet authentication via agentmail.to.
  • Performs infrastructure availability checks through stabledomains.dev.
  • These domains represent infrastructure within the vendor's ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 07:34 PM
Security Audit — agent-trust-hub — self-evolving-agent