crunch-compete
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands for environment management (venv), package installation (pip), and competition workflows via the crunch-cli tool.
- [EXTERNAL_DOWNLOADS]: Fetches required libraries and competition-specific SDKs (e.g., crunch-cli, crunch-synth) from PyPI and interacts with the vendor's official hub at hub.crunchdao.com.
- [COMMAND_EXECUTION]: The skill ingests and analyzes competition code and documentation, which serves as a potential surface for indirect prompt injection. This is addressed by explicit safety rules for the agent regarding token handling and package installation.
Audit Metadata