{"data":{"skill":{"slug":"internet-court-nansen-smart-money-tracker","name":"nansen-smart-money-tracker","icon":"📦","repo":"https://github.com/internet-court/internet-court-skill/tree/main/vendored/nansen/nansen-smart-money-tracker","status":"approved","author":"internet-court","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"44d54e27-74c2-4dad-83fd-f770b4b3145c","skill_id":"38a1c621-9bc0-4a7d-b0b4-8e1fe577edad","version":1,"content_hash":"cdc6c99a59cefe5c5f7e0fcdcbd19e2a","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"The reviewed file is a short command guide for Nansen smart money CLI usage. Static external-command hits are Markdown examples and inline backtick formatting, and environment hits only declare the required Nansen API key. No prompt injection or malicious data-exfiltration intent was found.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":37,"line_start":25},{"file":"SKILL.md","line_end":41,"line_start":37},{"file":"SKILL.md","line_end":45,"line_start":41},{"file":"SKILL.md","line_end":46,"line_start":45},{"file":"SKILL.md","line_end":47,"line_start":46},{"file":"SKILL.md","line_end":48,"line_start":47},{"file":"SKILL.md","line_end":49,"line_start":48},{"file":"SKILL.md","line_end":50,"line_start":49},{"file":"SKILL.md","line_end":52,"line_start":50},{"file":"SKILL.md","line_end":54,"line_start":52},{"file":"SKILL.md","line_end":60,"line_start":54},{"file":"SKILL.md","line_end":61,"line_start":60},{"file":"SKILL.md","line_end":62,"line_start":61},{"file":"SKILL.md","line_end":63,"line_start":62},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":65,"line_start":64},{"file":"SKILL.md","line_end":66,"line_start":65},{"file":"SKILL.md","line_end":70,"line_start":66},{"file":"SKILL.md","line_end":70,"line_start":70}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":8,"line_start":8},{"file":"SKILL.md","line_end":11,"line_start":11}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":72,"audit_model":"codex","audited_at":"2026-07-10T00:04:51.085+00:00","created_at":"2026-07-10T07:43:51.72001+00:00","static_findings":[{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"All commands: `nansen research smart-money <sub> [options]`","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":37,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":41,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Filter by smart money category with `--labels`:","category":"external_commands","line_end":45,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Fund` | Crypto funds |","category":"external_commands","line_end":46,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Smart Trader` | All-time top performers |","category":"external_commands","line_end":47,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `30D Smart Trader` | Hot hands — top 30 days |","category":"external_commands","line_end":48,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `90D Smart Trader` | Top 90 days |","category":"external_commands","line_end":49,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `180D Smart Trader` | Top 180 days |","category":"external_commands","line_end":50,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Smart HL Perps Trader` | Top Hyperliquid perp traders |","category":"external_commands","line_end":52,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":54,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":60,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--chain` | Required for netflow/dex-trades/holdings |","category":"external_commands","line_end":61,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--labels` | Filter by SM label (quote multi-word values) |","category":"external_commands","line_end":62,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--limit` | Number of results |","category":"external_commands","line_end":63,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--sort` | Sort field:direction (e.g. `value_usd:desc`) |","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--fields` | Select specific fields |","category":"external_commands","line_end":65,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--table` | Human-readable table output |","category":"external_commands","line_end":66,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--format csv` | CSV export |","category":"external_commands","line_end":70,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `perp-trades` is Hyperliquid-only. No `--chain` flag.","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"env_access:SKILL.md:8:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"- NANSEN_API_KEY","category":"env_access","line_end":8,"severity":"high","line_start":8},{"id":"env_access:SKILL.md:11:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"primaryEnv: NANSEN_API_KEY","category":"env_access","line_end":11,"severity":"high","line_start":11},{"id":"blocker:SKILL.md:35:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"# Perp trades — Hyperliquid only (no --chain needed)","category":"blocker","line_end":35,"severity":"low","line_start":35},{"id":"blocker:SKILL.md:50:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| `Smart HL Perps Trader` | Top Hyperliquid perp traders |","category":"blocker","line_end":50,"severity":"low","line_start":50}],"finding_verdicts":[{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"Line 21 is Markdown inline code documenting the nansen CLI command shape. It does not execute a command or interpolate user input.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"Lines 25-37 are a fenced bash example block for explicit nansen CLI use. The skill file contains documentation, not Ruby backtick execution.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"Line 37 closes a Markdown code fence. It is formatting syntax and does not execute shell commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"Line 41 uses Markdown backticks around the --labels flag. It is documentation text, not command substitution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"Line 45 formats the Fund label in a Markdown table. It does not run a command or evaluate code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"Line 46 formats the Smart Trader label in a Markdown table. There is no shell execution behavior on this line.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"Line 47 formats a Nansen label in Markdown backticks. It is static documentation, not executable code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"Line 48 formats a Nansen label in Markdown backticks. It contains no command execution primitive.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"Line 49 formats a Nansen label in Markdown backticks. The table entry is not executable.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"Line 50 formats the Smart HL Perps Trader label in a Markdown table. It does not execute or expand shell input.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"Lines 52-54 are a fenced bash example for a nansen netflow query. It is visible usage documentation, not hidden shell execution.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"Line 54 closes a Markdown code fence. The scanner matched formatting syntax, not an executable construct.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"Line 60 formats the --chain flag in a Markdown table. It is descriptive text and does not launch a process.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"Line 61 formats the --labels flag in a Markdown table. It is not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"Line 62 formats the --limit flag in Markdown. It is static documentation only.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"Line 63 formats the --sort flag and an example sort value. It does not execute command substitution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"Line 64 formats the --fields flag in Markdown. It is safe documentation text.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"Line 65 formats the --table flag in Markdown. There is no command execution behavior.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"Line 66 formats the --format csv option in Markdown. It documents an export option without executing code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"Line 70 uses Markdown backticks for a subcommand and flag name. It is a note about CLI usage, not executable code.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:8:generic-api-secret-keys","reason":"Line 8 declares NANSEN_API_KEY as a required environment variable for authenticated Nansen CLI access. It does not read, print, or transmit the secret.","verdict":"false_positive","confidence":0.87},{"id":"env_access:SKILL.md:11:generic-api-secret-keys","reason":"Line 11 identifies NANSEN_API_KEY as the primary environment variable. This is configuration metadata, not secret exfiltration.","verdict":"false_positive","confidence":0.87},{"id":"blocker:SKILL.md:35:system-reconnaissance","reason":"Line 35 describes Hyperliquid-only perpetual trade data. It does not request host, network, or system reconnaissance.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:50:system-reconnaissance","reason":"Line 50 names a Nansen trader label in a Markdown table. It has no system reconnaissance behavior.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}