endaoment

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs network operations against standard, official endpoints including the Endaoment API (api.endaoment.org) and the Base mainnet RPC (mainnet.base.org) to fetch charity metadata and contract status.
  • [SAFE]: Command execution is limited to essential system utilities (curl, jq, bc, xxd) and the bankr CLI, which is the required interface for transaction management in this environment. The scripts handle user inputs (EIN and Amount) using standard shell variable expansion and do not utilize dangerous functions like eval or exec on unvalidated data.
  • [SAFE]: No evidence of data exfiltration, credential harvesting, or malicious persistence was found. The skill relies on external configuration for the Bankr platform rather than hardcoding secrets or accessing sensitive system files.
  • [SAFE]: The skill uses clear, non-deceptive metadata that accurately reflects its functionality and requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 10:16 AM
Security Audit — agent-trust-hub — endaoment