crypto-onchain
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to gather data from external web searches (whales, exchange flows, active addresses) and synthesize it into a report, which exposes the agent to untrusted content that could contain adversarial instructions. * Ingestion points: Multiple WebSearch queries defined in SKILL.md (e.g., searches for whale activity and exchange flows). * Boundary markers: The instructions lack explicit delimiters or safety prompts to tell the agent to ignore any embedded commands within the search results. * Capability inventory: The skill is primarily focused on generating a markdown report and does not demonstrate dangerous shell or network exfiltration capabilities. * Sanitization: There is no logic for sanitizing or filtering the content retrieved from external search providers before processing.
Audit Metadata