injective-trading-autosign

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: References the official '@injectivelabs/sdk-ts' package (version 1.17.8) and the InjectiveLabs GitHub repository. These are verified vendor resources necessary for the skill's functionality.
  • [DATA_EXFILFILTRATION]: Workflow involves the use of a keystore password for signing grant transactions. The documentation uses placeholders ('****') for sensitive inputs and frames them as one-time requirements, adhering to standard security practices for wallet-related tooling.
  • [PROMPT_INJECTION]: The skill addresses potential indirect prompt injection by providing specific instructions to the agent to reject requests for dangerous transaction types like 'MsgSend' or 'MsgWithdraw'. Ingestion points: User prompts in 'references/sample-prompts.md'; Boundary markers: Not specified; Capability inventory: 'authz_grant' and 'authz_revoke' activities; Sanitization: Explicit instruction to only allow trading-specific message types.
  • [COMMAND_EXECUTION]: Facilitates on-chain operations through defined 'authz_grant' and 'authz_revoke' commands meant for use with an Injective MCP server, which is consistent with the skill's intended purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 10:16 AM