safe-multisig-on-abstract
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill uses placeholders like
OWNER_1_PRIVATE_KEY,DEPLOYER_PRIVATE_KEY, and0xOwner1Address. It also contains a specific 'Gotchas' section that warns users to 'Never store private keys in client code' and recommends secure alternatives like environment variables or KMS. This is a security best practice. - [EXTERNAL_DOWNLOADS]: The skill instructs users to install standard, well-known libraries from the
@safe-globalorganization (Protocol Kit) via npm. These are the official tools for Safe wallet management. - [COMMAND_EXECUTION]: The code examples demonstrate standard blockchain transaction patterns, such as deploying a smart contract and signing/executing multi-sig transactions. The use of shell commands is limited to standard package installations (
npm install). - [DATA_EXFILTRATION]: There is no evidence of sensitive data being sent to external or unauthorized servers. Network operations are directed towards official Abstract RPC endpoints (
api.mainnet.abs.xyz) and the official Safe UI (safe.abs.xyz).
Audit Metadata