building-on-abstract
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing several NPM packages and using scaffolding tools. These include vendor-owned packages like
@abstract-foundation/create-abstract-app,@abstract-foundation/agw-client, and@abstract-foundation/agw-react. It also references well-known industry libraries such asviem,wagmi, and@tanstack/react-query, as well as ZKsync-specific tools from@matterlabs. These are standard requirements for the stated purpose of the skill. - [COMMAND_EXECUTION]: The instructions provide standard CLI commands for developers, including
npxfor project creation andforgeoragwfor smart contract deployment. These commands are typical for a development environment and are directed toward official or well-known tooling. - [REMOTE_CODE_EXECUTION]: There are no patterns involving the execution of remote scripts via piping to a shell (e.g.,
curl | bash). All external references are to official documentation, GitHub repositories of the vendor, or well-known ecosystem providers. - [DATA_EXFILTRATION]: The skill mentions official RPC endpoints (
api.mainnet.abs.xyz,api.testnet.abs.xyz) and explorers (abscan.org). These are the standard infrastructure components for the Abstract network and do not represent a data exfiltration risk. - [SAFE]: The system contract addresses and registry addresses provided are consistent with the Abstract and ZKsync ecosystem technical specifications.
Audit Metadata