crypto-bd-agent

Pass

Audited by Gen Agent Trust Hub on Mar 1, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a workflow where the agent processes untrusted data from external sources, which constitutes a risk for indirect prompt injection. \n * Ingestion points: The architecture relies on external data from web scraping (Firecrawl), social media metrics, and protocol forums.\n * Boundary markers: The pattern does not specify delimiters or instructions to prevent the agent from obeying commands embedded in the fetched data.\n * Capability inventory: The agent is designed to manage outreach pipelines, draft communications, and handle micropayments via the x402 protocol.\n * Sanitization: The documentation mitigates risk by requiring human-in-the-loop approval before any outreach is sent.\n- [EXTERNAL_DOWNLOADS]: The markdown file contains a reference link to a GitHub repository from an untrusted community source.\n * Evidence: Link to 'https://github.com/buzzbysolcex/buzz-bd-agent' provided as a reference implementation.\n- [NO_CODE]: This skill consists entirely of markdown documentation and architectural guidance. No executable scripts, binaries, or automation files are included in the package.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 1, 2026, 09:46 AM