skills/bankrbot/skills/azzle/Gen Agent Trust Hub

azzle

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches blockchain and task-related data from external network endpoints.
  • Evidence: Connects to base-rpc.publicnode.com to interact with the Base mainnet via RPC calls.
  • Evidence: Communicates with azzle.org APIs to retrieve marketplace metadata and task listings.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the task marketplace, such as task descriptions and scopes.
  • Ingestion points: Untrusted task metadata and off-chain messages (XMTP) are processed in scripts/v2-lib.mjs and used to populate the agent's context.
  • Boundary markers: SKILL.md provides explicit instructions to the agent to treat all marketplace data as untrusted and never to use it to authorize code execution or transactions.
  • Capability inventory: The skill has the ability to execute on-chain transactions and bounded approvals via the bankr tool.
  • Sanitization: The skill implements a robust defense-in-depth strategy, requiring the agent to verify all contract addresses, runtime code hashes, and implementation code hashes against a reviewed 'pinned' configuration before every write.
  • [COMMAND_EXECUTION]: The skill uses local shell scripts and CLI tools to verify blockchain state and execute transactions.
  • Evidence: Executes ./scripts/v2-tasks.sh to perform integrity checks on deployed contracts.
  • Evidence: Uses the bankr CLI for wallet operations and transaction signing, with mandatory local decoding and user confirmation steps defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:46 AM
Security Audit — agent-trust-hub — azzle