erc8004-on-abstract

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as a reference and implementation guide for the ERC-8004 protocol. All code snippets and contract addresses are consistent with the stated purpose of enabling onchain agent identity and reputation.
  • [SAFE]: Secret management follows industry standards by using environment variables (e.g., process.env.PRIVATE_KEY) to handle sensitive wallet information.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for ingesting external agent metadata and onchain feedback data.
  • Ingestion points: External agent metadata JSON files (referenced in SKILL.md and references/agent-uri-schema.md) and reputation feedback entries read from the ReputationRegistry contract.
  • Boundary markers: None explicitly defined in the provided implementation examples, though the protocol enforces a JSON schema for agent URIs.
  • Capability inventory: Writing to and reading from smart contracts on the Abstract mainnet using the viem library.
  • Sanitization: The documentation provides explicit guidance on mitigating malicious data (Sybil attacks) by filtering reputation queries through trusted clientAddresses.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:30 AM
Security Audit — agent-trust-hub — erc8004-on-abstract