solidity-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches smart contract libraries and deployment tools from OpenZeppelin's public GitHub repositories using the forge install command.
  • [DYNAMIC_EXECUTION]: The deployment workflow requires the use of the --ffi (Foreign Function Interface) flag in Foundry. This feature allows Solidity scripts to execute external shell commands, which is required by the OpenZeppelin Upgrades plugin to perform storage layout validation, but it also creates a surface for the execution of arbitrary shell processes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided deployment tasks and scripts which could contain malicious instructions.
  • Ingestion points: User-supplied deployment tasks and Solidity script files (*.s.sol).
  • Boundary markers: None identified to separate instructions from data.
  • Capability inventory: File system access, network operations via forge and cast, and shell execution via the FFI capability.
  • Sanitization: No input validation or sanitization routines are specified for external content processed by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 08:20 AM
Security Audit — agent-trust-hub — solidity-deploy