@1390/woofi-data

Pass

Audited by Gen Agent Trust Hub on May 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill communicates with external API endpoints at api.woofi.com and sapi.woofi.com to fetch decentralized exchange analytics, pricing quotes, and transaction data. These domains are official resources for the WOOFi protocol, a well-known DeFi service.
  • [COMMAND_EXECUTION]: Includes Python scripts (total_tvl.py, total_volume.py) used to automate data aggregation across multiple blockchain networks. These scripts perform standard network requests and mathematical calculations using the requests library, consistent with the skill's documented purpose.
  • [DATA_EXFILTRATION]: While the skill processes user wallet addresses, it does so to facilitate the generation of on-chain transaction payloads via the WOOFi API. This is a standard requirement for DeFi trade execution and does not represent unauthorized data collection.
  • [SAFE]: A thorough review of the skill's instructions, metadata, and scripts found no evidence of prompt injection, obfuscation, or persistence mechanisms. The behavior is transparent and aligns with established best practices for protocol integrations.
Audit Metadata
Risk Level
SAFE
Analyzed
May 21, 2026, 03:36 AM
Security Audit — agent-trust-hub — @1390/woofi-data