ai-trader-tradesync

Warn

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download of remote configuration content from https://ai4trade.ai/skill/tradesync during the installation process.- [REMOTE_CODE_EXECUTION]: Describes an automated installation pattern where the agent fetches content from a remote URL (https://ai4trade.ai/skill/tradesync) to be parsed and used for skill setup, which could execute arbitrary instructions provided by the remote server.- [COMMAND_EXECUTION]: Provides instructions to execute shell commands using the openclaw utility to install third-party plugins (@clawtrader/tradesync), configure authentication tokens, and restart gateway services.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 25, 2026, 04:46 AM