aeon-distribute-tokens
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of recipient handles which are subsequently resolved into wallet addresses using a prompt-based Agent API (
POST /agent/prompt). - Ingestion points: Recipient handles provided in the configuration YAML or trigger phrases.
- Boundary markers: No specific delimiters or safety instructions are defined to prevent the agent from being misled during handle resolution.
- Capability inventory: The skill possesses the capability to initiate financial transactions via the sanctioned
POST /wallet/transferendpoint. - Sanitization: The documentation does not specify any validation or sanitization steps for handle strings before they are passed to the resolution agent.
- [DATA_EXFILTRATION]: The skill performs network operations to external endpoints.
- Network operations: It makes
curlrequests toapi.bankr.botfor preflight identity checks, portfolio balance inquiries, and token transfers. These endpoints are associated with the skill author's infrastructure.
Audit Metadata