lunarcrush
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external sources including social media posts, news articles, and influencer profiles, which are then integrated into the agent's context.
- Ingestion points: Untrusted content is fetched via several tools, notably in
tools/topics.py(through functions likeget_topic_postsandget_topic_news),tools/creators.py(viaget_creator_posts), andtools/coins.py(viaget_coin_meta). - Boundary markers: The skill lacks explicit boundary markers or instructional delimiters that would advise the agent to treat the fetched content as data only and ignore any embedded commands or instructions.
- Capability inventory: The skill operates in an environment with network access (provided by
proxied_getintools/utils.py) and standard file system access, which are potential targets for exploitation if an injection attack is successful. - Sanitization: Content retrieved from the LunarCrush API (such as post bodies, news titles, and descriptions) is passed to the agent without sanitization or filtering to detect potential prompt injection attempts.
Audit Metadata