nansen-trading
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill installs the 'nansen-cli' Node.js package from the official registry. This package is maintained by the skill's author, nansen-ai, and is considered a legitimate vendor resource.
- [SAFE]: The management of the 'NANSEN_WALLET_PASSWORD' environment variable follows safe practices for secret management, specifically by utilizing local environment files in the user's home directory to persist sensitive credentials.
- [SAFE]: Command execution is restricted to the 'nansen' binary through the 'allowed-tools' configuration, ensuring the agent cannot execute arbitrary shell commands.
- [SAFE]: No patterns of prompt injection, multi-layer obfuscation, or unauthorized data exfiltration were identified. The skill's technical operations are consistent with its documented purpose of facilitating blockchain transactions.
Audit Metadata