cremonix-signals
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches market regime data and subscription metadata from official vendor-controlled domains, specifically
blog.cremonix.comandapp.cremonix.com. These activities are required for the skill's functionality. - [COMMAND_EXECUTION]: Wrapper and example scripts utilize
curlandjqfor interacting with the Cremonix API and parsing JSON responses. Theagent-subscribe.pyscript also performs file I/O on~/.openclaw/openclaw.jsonto persistently store the API key, which is an expected behavior for this type of skill. - [SAFE]: Detailed analysis found no instances of prompt injection, data exfiltration, or obfuscation. The skill's design focuses on providing systematic trading edge through its 36-model ensemble and follows standard practices for API-integrated services.
Audit Metadata