aeon-distribute-tokens

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of recipient handles which are subsequently resolved into wallet addresses using a prompt-based Agent API (POST /agent/prompt).
  • Ingestion points: Recipient handles provided in the configuration YAML or trigger phrases.
  • Boundary markers: No specific delimiters or safety instructions are defined to prevent the agent from being misled during handle resolution.
  • Capability inventory: The skill possesses the capability to initiate financial transactions via the sanctioned POST /wallet/transfer endpoint.
  • Sanitization: The documentation does not specify any validation or sanitization steps for handle strings before they are passed to the resolution agent.
  • [DATA_EXFILTRATION]: The skill performs network operations to external endpoints.
  • Network operations: It makes curl requests to api.bankr.bot for preflight identity checks, portfolio balance inquiries, and token transfers. These endpoints are associated with the skill author's infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:44 AM
Security Audit — agent-trust-hub — aeon-distribute-tokens