coinstats-fiats

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the coinstats-cli Node.js package. This is a vendor-owned resource from the author, coinstatshq, and is considered safe.\n- [CREDENTIALS_UNSAFE]: The skill requires the COINSTATS_API_KEY environment variable for authentication. It provides setup instructions using a placeholder, which is a standard and safe practice.\n- [PROMPT_INJECTION]: The skill retrieves data from the CoinStats public API, creating a surface for indirect prompt injection.\n
  • Ingestion points: SKILL.md (data from coinstats fiats list command).\n
  • Boundary markers: Absent.\n
  • Capability inventory: Bash(coinstats:*) in SKILL.md.\n
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 04:52 AM