{"data":{"skill":{"slug":"internet-court-nansen-wallet-profiler","name":"nansen-wallet-profiler","icon":"📦","repo":"https://github.com/internet-court/internet-court-skill/tree/main/vendored/nansen/nansen-wallet-profiler","status":"approved","author":"internet-court","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"74105078-ff9d-4b1e-bb18-2c688e6c1943","skill_id":"9460bb73-5122-450a-a06e-f583d4a6b8a5","version":1,"content_hash":"2dbec735e9d0d7ac018a50ec1b77cf34","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Static findings were reviewed against SKILL.md. The external command hits are Markdown code spans or fences documenting Nansen CLI usage, and the env hits only declare NANSEN_API_KEY as required configuration. No prompt injection, credential exfiltration, or hidden override instructions were found.","remediation":[{"issue":"API key handling is documented only as required metadata.","severity":"low","suggestion":"Add setup guidance that tells users to keep NANSEN_API_KEY in environment variables and never paste it into prompts."},{"issue":"Trace and batch commands can consume many Nansen API calls.","severity":"low","suggestion":"Keep conservative defaults visible and ask users to confirm large depth, width, or batch runs."},{"issue":"Batch mode can read wallet addresses from a local file path.","severity":"low","suggestion":"Ask users to confirm the intended file path before using the documented --file option."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":31,"line_start":27},{"file":"SKILL.md","line_end":35,"line_start":31},{"file":"SKILL.md","line_end":38,"line_start":35},{"file":"SKILL.md","line_end":42,"line_start":38},{"file":"SKILL.md","line_end":45,"line_start":42},{"file":"SKILL.md","line_end":49,"line_start":45},{"file":"SKILL.md","line_end":52,"line_start":49},{"file":"SKILL.md","line_end":56,"line_start":52},{"file":"SKILL.md","line_end":59,"line_start":56},{"file":"SKILL.md","line_end":63,"line_start":59},{"file":"SKILL.md","line_end":74,"line_start":63},{"file":"SKILL.md","line_end":80,"line_start":74},{"file":"SKILL.md","line_end":81,"line_start":80},{"file":"SKILL.md","line_end":82,"line_start":81},{"file":"SKILL.md","line_end":83,"line_start":82},{"file":"SKILL.md","line_end":84,"line_start":83},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":86,"line_start":85},{"file":"SKILL.md","line_end":87,"line_start":86},{"file":"SKILL.md","line_end":88,"line_start":87},{"file":"SKILL.md","line_end":89,"line_start":88},{"file":"SKILL.md","line_end":93,"line_start":89},{"file":"SKILL.md","line_end":94,"line_start":93},{"file":"SKILL.md","line_end":95,"line_start":94},{"file":"SKILL.md","line_end":95,"line_start":95},{"file":"SKILL.md","line_end":97,"line_start":96},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":98,"line_start":98}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":8,"line_start":8},{"file":"SKILL.md","line_end":11,"line_start":11}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":99,"audit_model":"codex","audited_at":"2026-07-10T00:12:45.558+00:00","created_at":"2026-07-10T07:43:52.017135+00:00","static_findings":[{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"All commands: `nansen research profiler <sub> [options]`","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`--address` and `--chain` required for most commands.","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":31,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":35,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":38,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":42,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":45,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":49,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":52,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":56,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":59,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":63,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":74,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":80,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--address` | Wallet address (required) |","category":"external_commands","line_end":81,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--chain` | Required except for perps and search |","category":"external_commands","line_end":82,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--days` | Lookback period (default 30) |","category":"external_commands","line_end":83,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--limit` | Number of results |","category":"external_commands","line_end":84,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--include` | Batch fields: `labels,balance,pnl` |","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--depth` | Trace depth 1-5 (default 2) |","category":"external_commands","line_end":86,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--width` | Trace width — keep low to save credits |","category":"external_commands","line_end":87,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--fields` | Select specific fields |","category":"external_commands","line_end":88,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--table` | Human-readable table output |","category":"external_commands","line_end":89,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--format csv` | CSV export |","category":"external_commands","line_end":93,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `pnl-summary` has no pagination support (returns aggregate stats, not a list).","category":"external_commands","line_end":94,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `perp-positions` has no pagination support.","category":"external_commands","line_end":95,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `labels` has no pagination support — the API ignores `per_page` and always returns all labels for ","category":"external_commands","line_end":95,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `transactions` caps at per_page=100 (API limit).","category":"external_commands","line_end":97,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `trace` makes many API calls — use `--width` conservatively.","category":"external_commands","line_end":97,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `batch` accepts `--file <path>` with one address per line as alternative to `--addresses`.","category":"external_commands","line_end":98,"severity":"medium","line_start":98},{"id":"env_access:SKILL.md:8:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"- NANSEN_API_KEY","category":"env_access","line_end":8,"severity":"high","line_start":8},{"id":"env_access:SKILL.md:11:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"primaryEnv: NANSEN_API_KEY","category":"env_access","line_end":11,"severity":"high","line_start":11}],"finding_verdicts":[{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"This is Markdown inline code documenting Nansen CLI syntax. It is not Ruby or shell backtick execution, and no dynamic evaluation appears in SKILL.md.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"This is Markdown inline code documenting Nansen CLI syntax. It is not Ruby or shell backtick execution, and no dynamic evaluation appears in SKILL.md.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"This entry points to a Markdown code fence, not runtime shell backtick execution. The enclosed nansen examples are documentation with no dynamic evaluation in SKILL.md.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"This is Markdown inline code naming a CLI flag or note. It does not execute a command or perform shell substitution.","verdict":"false_positive","confidence":0.96},{"id":"env_access:SKILL.md:8:generic-api-secret-keys","reason":"This is a YAML metadata declaration that NANSEN_API_KEY is required. The file does not print, transmit, or expose the secret value.","verdict":"false_positive","confidence":0.93},{"id":"env_access:SKILL.md:11:generic-api-secret-keys","reason":"This only selects NANSEN_API_KEY as the primary setup environment variable. No secret value is embedded or exfiltrated in SKILL.md.","verdict":"false_positive","confidence":0.93}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}