web3-hunt-foundation

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of markdown-based documentation and guidelines. It contains no executable scripts, binaries, or obfuscated content. The mentioned tools (Foundry, Slither, Aderyn) and commands (git, forge) are standard industry utilities for the described purpose of smart contract auditing.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow that involves cloning and analyzing untrusted external codebases and prior audit reports, which creates a potential attack surface for indirect prompt injection.
  • Ingestion points: External target repositories and third-party audit reports (SKILL.md).
  • Boundary markers: The skill does not define specific delimiters or instructions for the agent to ignore potentially malicious content embedded in the target source code.
  • Capability inventory: The audit methodology involves executing shell commands for cloning repositories and running static analysis tools.
  • Sanitization: No pre-sanitization or filtering of the ingested source code is described, as the primary purpose is the raw analysis of that code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 05:38 AM
Security Audit — agent-trust-hub — web3-hunt-foundation