skills/bankrbot/skills/alchemy/Gen Agent Trust Hub

alchemy

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill provides comprehensive instructions for handling blockchain private keys and API keys. It mitigates the risk of credential exposure by mandating the use of shell pipes to move keys and explicitly forbidding the use of agent tools for reading sensitive configuration files.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it processes external blockchain data, including NFT metadata and webhook payloads. However, the documentation includes clear directives to treat this external content as untrusted and to perform proper sanitization before processing.
  • [DYNAMIC_EXECUTION]: The skill uses Node.js snippets executed via the CLI to generate authentication tokens (SIWE/SIWS). These operations are a standard part of the protocol's secure wallet-based authentication flow and are necessary for communicating with the Alchemy gateways.
  • [EXTERNAL_DOWNLOADS]: The skill setup requires installing several Node.js packages from established registries to handle blockchain interactions and payment protocols. These are legitimate service-related dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — alchemy