crypto-bd-agent
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that ingests data from untrusted external sources such as web scraping, social media metrics, and community forums, which creates a potential surface for indirect prompt injection.
- Ingestion points: Mentions data gathering from Firecrawl, protocol forums, and social media momentum trackers.
- Boundary markers: The skill implements a critical safety boundary by requiring 'Human-in-the-loop' oversight and explicit human approval for all outreach drafts before they are sent.
- Capability inventory: The architecture includes network communication for data collection, drafting outreach, and performing micropayments via the x402 protocol.
- Sanitization: The 'Security Rules' section specifically instructs the agent to flag prompt injection attempts immediately.
- [EXTERNAL_DOWNLOADS]: The skill provides links to external resources, including a reference implementation on GitHub (github.com/buzzbysolcex/buzz-bd-agent) and various blockchain data APIs (DexScreener, GeckoTerminal, Helius, Allium).
- [DATA_EXFILTRATION]: While the skill discusses autonomous micropayments (x402), it mandates the use of separate wallets for payments and verified endpoints to prevent unauthorized fund drainage or credential exposure. It also includes a rule against sharing API keys or private keys.
Audit Metadata