lighter
Pass
Audited by Gen Agent Trust Hub on Feb 20, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE] (SAFE): The analyzed skill consists solely of documentation and metadata. No executable scripts, binaries, or configuration files that could contain malicious logic were found.
- [CREDENTIALS_UNSAFE] (SAFE): The documentation mentions the requirement for an EVM_PRIVATE_KEY environment variable. All examples use non-sensitive placeholders ('0x...'), and no actual secrets are hardcoded in the file.
- [INDIRECT_PROMPT_INJECTION] (LOW): The skill provides an interface to interact with external blockchain data, which represents a theoretical attack surface for indirect prompt injection. Ingestion points: Market data, price feeds, and orderbook depth from the Arbitrum network. Boundary markers: Not present in the documentation. Capability inventory: Commands for opening/closing financial positions and managing orders. Sanitization: Not applicable as no processing logic is provided in this file.
Audit Metadata