elfa

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download and install its logic from an external repository (elfa-ai/skills) using the npx skills add command. This is documented as a standard onboarding procedure for the service.
  • [COMMAND_EXECUTION]: Provides shell command instructions for installation, updates, and setting environment variables for API key management (export ELFA_API_KEY).
  • [INDIRECT_PROMPT_INJECTION]: The skill's stated purpose involves ingesting real-time data from social media platforms (Twitter and Telegram) to drive automated trading and alerts. This integration creates a surface where untrusted external content could attempt to influence the agent's decision-making process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 07:30 AM
Security Audit — agent-trust-hub — elfa