upbit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with the Upbit API to fetch real-time market data, trade history, and account balances. This information is processed by the agent, creating a surface where malicious or manipulated data from the exchange could attempt to influence the agent's behavior.
- Ingestion points: The agent processes data from various Upbit API endpoints via CLI commands such as
tickers,candles,orderbooks, andorders list. - Boundary markers: The skill includes a robust safety protocol requiring the agent to display the full command and obtain an explicit
CONFIRMfrom the user before executing any write operations, such as placing orders or initiating withdrawals. - Capability inventory: The skill leverages the
upbitCLI tool, which has the capability to perform financial transactions and account management. The agent also has access tobashfor network utilities. - Sanitization: The skill relies on the
upbitCLI for data retrieval and formatting, but there is no explicit validation or sanitization step defined for the content received from the external API before the agent processes it. - [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the Upbit CLI tool and connects to a public service to discover the system's IP address.
- Evidence: Instructions in
references/setup.mdguide the installation of@upbit-official/upbit-clifrom the npm registry. InSKILL.md, the agent is directed to callbash("curl -s https://api.ipify.org")to assist the user with API key configuration. - [COMMAND_EXECUTION]: The skill makes extensive use of the
upbitCLI to interact with exchange services and uses shell commands for configuration tasks. - Evidence: The
SKILL.mdand reference files define numerous subcommands for theupbitbinary to manage accounts, orders, and market data, all executed via the system shell.
Audit Metadata