@6522/deepresearch
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Instructions direct the agent to utilize command-line tools like
curlto verify network status and service availability (e.g., "5s curl beats arguing"). - [REMOTE_CODE_EXECUTION]: The instructions reference a quantitative framework hosted on GitHub (github.com/tangtrades/lisa_quant) for data analysis and backtesting modules.
- [DATA_EXFILTRATION]: The skill aggregates data from diverse external financial APIs and web sources, while also maintaining the capability to output or host data through Vercel and PDF generation tools.
- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing untrusted data from web fetches and social media sentiment while possessing access to high-impact capabilities such as financial account management and trade execution.
- Ingestion points: External data is retrieved via tools like
web_search,web_fetch, and social media monitoring tools. - Boundary markers: The instructions do not define explicit delimiters for untrusted data, though they emphasize manual verification and cross-referencing.
- Capability inventory: Includes trade execution (
hyperliquid), financial account access (binance-account,okx-account), and deployment capabilities. - Sanitization: No specific sanitization or filtering procedures for external content are defined within the skill.
Audit Metadata