upgrade-l2

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill follows security best practices by instructing users to manage sensitive data such as the DEPLOYER_PRIVATE_KEY via a .env file and explicitly directs the agent never to ask for the actual key.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to run local deployment scripts and the npx hardhat command. These operations involve processing user-provided inputs such as RPC URLs and git tags.
  • [SAFE]: The skill uses well-known development tools and official smart contract addresses associated with the vendor. No patterns of data exfiltration, obfuscation, or unauthorized persistence were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 01:03 AM
Security Audit — agent-trust-hub — upgrade-l2