solidity-checklist

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates the use of the Foundry toolkit (cast and forge) to perform on-chain checks. These commands are part of the intended functionality for verifying contract state and permissions.
  • [INDIRECT_PROMPT_INJECTION]: The preflight flow requires the agent to read external smart contract source code to identify roles and dependencies. This involves processing untrusted data which could contain malicious instructions. Evidence chain: (1) Ingestion points: contract source code and RPC responses; (2) Boundary markers: None mentioned for external data; (3) Capability inventory: sensitive operations like cast send and forge script are available; (4) Sanitization: No explicit sanitization of ingested code or data.
  • [SAFE]: The skill promotes strong security best practices. It explicitly forbids the use of raw private keys in command-line arguments and instead mandates the use of secure keystores via cast wallet import.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 08:20 AM
Security Audit — agent-trust-hub — solidity-checklist