tokenomist
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill requires the
TOKENMIST_API_KEYenvironment variable. This follows the platform's recommended practice for secure secret management and avoids hardcoding credentials. Network requests are performed using the platform-providedproxied_gethelper and are targeted exclusively at the officialhttps://api.tokenomist.aidomain. - [INDIRECT_PROMPT_INJECTION]: The skill processes structured JSON data from an external API. While this presents a theoretical attack surface where malicious metadata from the API could attempt to influence the agent, the risk is considered low given the reputable nature of the data source and the structured way the data is processed and presented to the LLM.
- [COMMAND_EXECUTION]: The
SKILL.mdfile contains a documentation block demonstrating how to invoke the skill's logic via a Python subprocess in a bash block. This is a standard integration pattern for script-mode skills on this platform and does not involve the execution of untrusted or dynamically generated code strings.
Audit Metadata