spider-strategy

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it consumes data from public trading leaderboards and market signals to drive its decision-making logic.\n- Ingestion points: Market data and leaderboard exposure counts enter the agent's context through the anchor_candidates and basket_candidates scanners defined in runtime.yaml.\n- Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands defined in the provided configuration to protect the LLM from instructions potentially embedded in external data fields.\n- Capability inventory: The skill possesses the capability to execute and manage trading positions, providing a pathway for malicious inputs to trigger financial actions.\n- Sanitization: No sanitization or validation of external market data is present in the provided scripts or configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 10:52 AM