skills/supurr-app/supurr_skill/supurr/Gen Agent Trust Hub

supurr

Pass

Audited by Gen Agent Trust Hub on Feb 24, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The installer scripts fetch and run installation logic directly from the developer's official domain (cli.supurr.app).
  • [EXTERNAL_DOWNLOADS]: The skill downloads the supurr CLI binary and its associated trading engine from the vendor's official release endpoint.
  • [CREDENTIALS_UNSAFE]: The tool manages Hyperliquid wallet addresses and private keys, storing them locally in credentials.json to enable automated trading and message signing.
  • [COMMAND_EXECUTION]: The skill modifies shell configuration files to update the system PATH and provides a suite of commands for the agent to manage the trading lifecycle.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 24, 2026, 09:13 PM