megaeth-developer

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and installs well-known, established libraries and dependencies from trusted organizations and well-known services. This includes OpenZeppelin contracts, Solady optimized utilities, Uniswap SDK components, Privy authentication libraries, and MetaMask Smart Accounts Kit. These references are documented neutrally as standard development requirements.
  • [COMMAND_EXECUTION]: The skill provides the agent with appropriate CLI commands (Foundry, cast, forge) to guide users in contract deployment and verification. These commands are informational templates for the user's development workflow rather than instructions for the agent to execute unauthorized or hidden operations.
  • [CREDENTIALS_UNSAFE]: Security best practices for credential management are explicitly followed. The instructions guide users to store sensitive data such as private keys in environment variables (.env) or dedicated wallet configuration files (~/.evm-wallet.json) with restricted permissions, rather than hardcoding them in the skill or scripts.
  • [SAFE]: The architecture utilizes official MegaETH and Meridian API endpoints for RPC operations and payment settlement. The guidance on low-latency signing (Privy) and transaction submission (EIP-7966) is consistent with the stated purpose of building real-time dApps and does not exhibit malicious intent or obfuscation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 03:15 PM