solidity-best-practice
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is comprised entirely of markdown documentation and YAML configuration files. There are no executable files (e.g., .py, .js, .sh) or binaries included in the skill package.
- [EXTERNAL_DOWNLOADS]: The skill contains references to the official Solidity documentation at docs.soliditylang.org for style guides and security considerations. These are well-known, trusted resources and do not involve automated script execution or the retrieval of unverifiable software packages.
- [PROMPT_INJECTION]: Analysis of the instructions revealed no attempts to override safety filters, disclose internal prompts, or manipulate agent behavior beyond the intended scope of Solidity code review.
- [DATA_EXFILTRATION]: No instructions or patterns were found that attempt to access sensitive system files, environment variables, or credentials. There are no network-capable tools configured or used.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes external code provided by the user, it lacks the dangerous capabilities (such as shell execution, file system modification, or network access) that would be necessary to exploit an indirect injection via code comments or data.
Audit Metadata