lunarcrush

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external sources including social media posts, news articles, and influencer profiles, which are then integrated into the agent's context.
  • Ingestion points: Untrusted content is fetched via several tools, notably in tools/topics.py (through functions like get_topic_posts and get_topic_news), tools/creators.py (via get_creator_posts), and tools/coins.py (via get_coin_meta).
  • Boundary markers: The skill lacks explicit boundary markers or instructional delimiters that would advise the agent to treat the fetched content as data only and ignore any embedded commands or instructions.
  • Capability inventory: The skill operates in an environment with network access (provided by proxied_get in tools/utils.py) and standard file system access, which are potential targets for exploitation if an injection attack is successful.
  • Sanitization: Content retrieved from the LunarCrush API (such as post bodies, news titles, and descriptions) is passed to the agent without sanitization or filtering to detect potential prompt injection attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — lunarcrush