NYC
skills/aahl/skills/crypto-report/Gen Agent Trust Hub

crypto-report

Fail

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection (HIGH): The skill ingests untrusted data from theblockbeats.news and binance.com which is then processed by an agent with shell execution capabilities.
  • Ingestion points: scripts/theblockbeats-news.sh and scripts/binance-ai-report.sh fetch content via curl.
  • Boundary markers: Absent. External text is provided to the agent without separation or safety warnings.
  • Capability inventory: SKILL.md defines shell execution as a primary function, providing a high-privilege context for any injected instructions.
  • Sanitization: None observed.
  • Command Execution (MEDIUM): The bash scripts take positional arguments that are interpolated into shell commands and URLs. In theblockbeats-news.sh, parameters like $PAGE and $SIZE are used directly in a URI, creating a risk of parameter manipulation.
  • Data Exposure (LOW): The skill performs network operations to non-whitelisted domains.
  • Logic Error (INFO): The script theblockbeats-news.sh references a $PAYLOAD variable that is never defined in that file.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 15, 2026, 09:07 PM