building-on-abstract

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing several NPM packages and using scaffolding tools. These include vendor-owned packages like @abstract-foundation/create-abstract-app, @abstract-foundation/agw-client, and @abstract-foundation/agw-react. It also references well-known industry libraries such as viem, wagmi, and @tanstack/react-query, as well as ZKsync-specific tools from @matterlabs. These are standard requirements for the stated purpose of the skill.
  • [COMMAND_EXECUTION]: The instructions provide standard CLI commands for developers, including npx for project creation and forge or agw for smart contract deployment. These commands are typical for a development environment and are directed toward official or well-known tooling.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the execution of remote scripts via piping to a shell (e.g., curl | bash). All external references are to official documentation, GitHub repositories of the vendor, or well-known ecosystem providers.
  • [DATA_EXFILTRATION]: The skill mentions official RPC endpoints (api.mainnet.abs.xyz, api.testnet.abs.xyz) and explorers (abscan.org). These are the standard infrastructure components for the Abstract network and do not represent a data exfiltration risk.
  • [SAFE]: The system contract addresses and registry addresses provided are consistent with the Abstract and ZKsync ecosystem technical specifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:30 AM
Security Audit — agent-trust-hub — building-on-abstract