crypto-defi
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process data from external sources such as governance forums and protocol dashboards, creating an attack surface for indirect prompt injection.
- Ingestion points: SKILL.md (Data Collection Phase 1 & 2) specifies fetching data from DeFiLlama, CoinGecko, Token Terminal, and governance forums (Snapshot, Tally).
- Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore embedded instructions' prompts to isolate untrusted data from the agent's execution logic.
- Capability inventory: The agent has the capability to perform web searches, fetch web content, and write analysis results to the filesystem (CRYPTO-DEFI-[PROTOCOL].md).
- Sanitization: Absent. There are no instructions for escaping, validating, or filtering the content retrieved from external URLs before interpolation into the final report.
Audit Metadata