crypto-onchain

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to gather data from external web searches (whales, exchange flows, active addresses) and synthesize it into a report, which exposes the agent to untrusted content that could contain adversarial instructions. * Ingestion points: Multiple WebSearch queries defined in SKILL.md (e.g., searches for whale activity and exchange flows). * Boundary markers: The instructions lack explicit delimiters or safety prompts to tell the agent to ignore any embedded commands within the search results. * Capability inventory: The skill is primarily focused on generating a markdown report and does not demonstrate dangerous shell or network exfiltration capabilities. * Sanitization: There is no logic for sanitizing or filtering the content retrieved from external search providers before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 01:34 AM
Security Audit — agent-trust-hub — crypto-onchain