coinmarketcap-agent-teneo
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides the agent with specific bash commands to be executed via a local CLI tool (
~/teneo-skill/teneo) for querying market data. - [DATA_EXFILTRATION]: The skill initiates network requests to the Teneo Protocol network and CoinMarketCap API. All identified domains, such as teneo-protocol.ai and coinmarketcap.com, are recognized as the vendor's own infrastructure or official, well-known industry services.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing data from an external API source. 1. Ingestion points: Cryptocurrency data retrieved from the CoinMarketCap API via the
teneocommand. 2. Boundary markers: Absent; no instructions are provided to distinguish data from instructions. 3. Capability inventory: Local command execution via theteneoCLI tool. 4. Sanitization: Absent; no validation or escaping steps are specified for the external content.
Audit Metadata