@6522/deepresearch

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Instructions direct the agent to utilize command-line tools like curl to verify network status and service availability (e.g., "5s curl beats arguing").
  • [REMOTE_CODE_EXECUTION]: The instructions reference a quantitative framework hosted on GitHub (github.com/tangtrades/lisa_quant) for data analysis and backtesting modules.
  • [DATA_EXFILTRATION]: The skill aggregates data from diverse external financial APIs and web sources, while also maintaining the capability to output or host data through Vercel and PDF generation tools.
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing untrusted data from web fetches and social media sentiment while possessing access to high-impact capabilities such as financial account management and trade execution.
  • Ingestion points: External data is retrieved via tools like web_search, web_fetch, and social media monitoring tools.
  • Boundary markers: The instructions do not define explicit delimiters for untrusted data, though they emphasize manual verification and cross-referencing.
  • Capability inventory: Includes trade execution (hyperliquid), financial account access (binance-account, okx-account), and deployment capabilities.
  • Sanitization: No specific sanitization or filtering procedures for external content are defined within the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:26 PM
Security Audit — agent-trust-hub — @6522/deepresearch