hodlmm-risk
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill makes network requests to
api.bitflow.financeto retrieve pool state, bin distributions, and user position data. These operations are limited to the official API of the service being monitored and do not involve downloading or executing external code. - [COMMAND_EXECUTION]: The script uses the
commanderlibrary to manage CLI arguments for pool identifiers and Stacks addresses. It does not perform arbitrary shell command execution or expose system-level vulnerabilities. - [DATA_EXFILTRATION]: The skill processes user-provided pool IDs and Stacks addresses to query public DeFi data. It does not access sensitive local files, environment variables, or credentials, and only communicates with the designated service domain.
Audit Metadata