treasures

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to download and install external code via npx skills add, specifically targeting the sc-vpn skill from the Starchild-ai-agent repository. While these are vendor-provided resources, they involve the dynamic acquisition of external instructions and tools during the skill's setup phase.
  • [COMMAND_EXECUTION]: The skill contains Python and Bash scripts designed for agent execution. These scripts include logic to interact with financial APIs and configure local proxy tunnels. Most notably, it provides explicit instructions to circumvent server-side geographical restrictions (HTTP 451 'Unavailable for Legal Reasons') by routing traffic through specific exit regions via an internal proxy service.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the Treasures Finance API, which represents an untrusted external data source that could influence agent behavior.
  • Ingestion points: JSON responses from https://api.treasures.io/public/v1/portfolio and quote endpoints (SKILL.md).
  • Boundary markers: Absent. The skill provides no delimiters or instructions for the agent to treat external API data as data only, leaving it susceptible to interpreting malicious instructions embedded in the payload.
  • Capability inventory: The agent has the ability to execute network requests, perform shell commands, and utilize a wallet tool for signing transactions.
  • Sanitization: There is no evidence of validation or sanitization of the API responses before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — treasures