treasures
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to download and install external code via
npx skills add, specifically targeting thesc-vpnskill from theStarchild-ai-agentrepository. While these are vendor-provided resources, they involve the dynamic acquisition of external instructions and tools during the skill's setup phase. - [COMMAND_EXECUTION]: The skill contains Python and Bash scripts designed for agent execution. These scripts include logic to interact with financial APIs and configure local proxy tunnels. Most notably, it provides explicit instructions to circumvent server-side geographical restrictions (HTTP 451 'Unavailable for Legal Reasons') by routing traffic through specific exit regions via an internal proxy service.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the Treasures Finance API, which represents an untrusted external data source that could influence agent behavior.
- Ingestion points: JSON responses from
https://api.treasures.io/public/v1/portfolioand quote endpoints (SKILL.md). - Boundary markers: Absent. The skill provides no delimiters or instructions for the agent to treat external API data as data only, leaving it susceptible to interpreting malicious instructions embedded in the payload.
- Capability inventory: The agent has the ability to execute network requests, perform shell commands, and utilize a
wallettool for signing transactions. - Sanitization: There is no evidence of validation or sanitization of the API responses before they are processed by the agent.
Audit Metadata