Audit History
nansen-token-research - 2 audits
Version comparison
Capability and finding changes across audited versions, newest first.
Jul 21, 2026, 03:40 AM
All 31 static findings are false positives caused by Markdown code formatting, CLI documentation, and environment-requirement metadata. The skill contains illustrative Nansen CLI queries only; no embedded shell execution, credential handling, reconnaissance, prompt injection, or exfiltration intent was found.
Risk Factors
⚙️ External commands (28)
🔑 Env variables (2)
Jul 10, 2026, 12:08 AM
Most static backtick findings are false positives from Markdown inline code and fenced command examples in SKILL.md. The API key findings declare required configuration, not hardcoded secrets. A semantic finding notes the broad Bash(nansen:*) tool allowance and recommends narrowing the command surface.