cremonix-signals

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches market regime data and subscription metadata from official vendor-controlled domains, specifically blog.cremonix.com and app.cremonix.com. These activities are required for the skill's functionality.
  • [COMMAND_EXECUTION]: Wrapper and example scripts utilize curl and jq for interacting with the Cremonix API and parsing JSON responses. The agent-subscribe.py script also performs file I/O on ~/.openclaw/openclaw.json to persistently store the API key, which is an expected behavior for this type of skill.
  • [SAFE]: Detailed analysis found no instances of prompt injection, data exfiltration, or obfuscation. The skill's design focuses on providing systematic trading edge through its 36-model ensemble and follows standard practices for API-integrated services.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 01:18 AM