@6522/tangcore-agent

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted data from external research sources (Perplexity, news, pitch materials). It implements a robust mitigation strategy by classifying this data as 'UNVERIFIED LEADS' and mandating an Evidence Ledger where every material claim must be re-verified against a primary source before use.
  • [EXTERNAL_DOWNLOADS]: The agent is instructed to interact with several well-known financial and crypto data APIs, including CoinGecko, DeFiLlama, and RootData, to fetch live evidence. It also specifies deploying output reports to Vercel. These network operations are consistent with the skill's primary purpose and utilize established, reputable service providers.
  • [COMMAND_EXECUTION]: The skill uses specialized tools for quantitative analysis (e.g., 'backtest', 'LISA_QUANT') and charts. These appear to be domain-specific tools integrated into the agent environment for its intended financial analysis tasks, with no evidence of arbitrary or dangerous command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 09:06 PM
Security Audit — agent-trust-hub — @6522/tangcore-agent