solidity-checklist
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates the use of the Foundry toolkit (
castandforge) to perform on-chain checks. These commands are part of the intended functionality for verifying contract state and permissions. - [INDIRECT_PROMPT_INJECTION]: The preflight flow requires the agent to read external smart contract source code to identify roles and dependencies. This involves processing untrusted data which could contain malicious instructions. Evidence chain: (1) Ingestion points: contract source code and RPC responses; (2) Boundary markers: None mentioned for external data; (3) Capability inventory: sensitive operations like
cast sendandforge scriptare available; (4) Sanitization: No explicit sanitization of ingested code or data. - [SAFE]: The skill promotes strong security best practices. It explicitly forbids the use of raw private keys in command-line arguments and instead mandates the use of secure keystores via
cast wallet import.
Audit Metadata