tokenomist

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill requires the TOKENMIST_API_KEY environment variable. This follows the platform's recommended practice for secure secret management and avoids hardcoding credentials. Network requests are performed using the platform-provided proxied_get helper and are targeted exclusively at the official https://api.tokenomist.ai domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured JSON data from an external API. While this presents a theoretical attack surface where malicious metadata from the API could attempt to influence the agent, the risk is considered low given the reputable nature of the data source and the structured way the data is processed and presented to the LLM.
  • [COMMAND_EXECUTION]: The SKILL.md file contains a documentation block demonstrating how to invoke the skill's logic via a Python subprocess in a bash block. This is a standard integration pattern for script-mode skills on this platform and does not involve the execution of untrusted or dynamically generated code strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — tokenomist