bybit-futures

Pass

Audited by Gen Agent Trust Hub on Feb 20, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • NO_CODE (SAFE): The provided file SKILL.md contains only documentation, command definitions, and metadata. No executable scripts, source code files, or binaries were included for analysis, meaning no direct malicious execution is possible from the provided content.\n- PROMPT_INJECTION (LOW): The skill design exposes a surface for Indirect Prompt Injection. Ingestion points: The skill reads external market data (prices, funding rates) from the Bybit API and trade history from a local database. Boundary markers: No delimiters or instructions to ignore embedded commands are present in the documentation. Capability inventory: The skill possesses high-impact capabilities, including opening/closing positions with up to 100x leverage and managing account orders. Sanitization: Sanitization and validation procedures are unverifiable as no implementation code was provided. This structure could allow malicious external data to influence the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 20, 2026, 08:51 PM