crypto-bd-agent
Pass
Audited by Gen Agent Trust Hub on Mar 1, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill defines a workflow where the agent processes untrusted data from external sources, which constitutes a risk for indirect prompt injection. \n * Ingestion points: The architecture relies on external data from web scraping (Firecrawl), social media metrics, and protocol forums.\n * Boundary markers: The pattern does not specify delimiters or instructions to prevent the agent from obeying commands embedded in the fetched data.\n * Capability inventory: The agent is designed to manage outreach pipelines, draft communications, and handle micropayments via the x402 protocol.\n * Sanitization: The documentation mitigates risk by requiring human-in-the-loop approval before any outreach is sent.\n- [EXTERNAL_DOWNLOADS]: The markdown file contains a reference link to a GitHub repository from an untrusted community source.\n * Evidence: Link to 'https://github.com/buzzbysolcex/buzz-bd-agent' provided as a reference implementation.\n- [NO_CODE]: This skill consists entirely of markdown documentation and architectural guidance. No executable scripts, binaries, or automation files are included in the package.
Audit Metadata