azzle
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches blockchain and task-related data from external network endpoints.
- Evidence: Connects to
base-rpc.publicnode.comto interact with the Base mainnet via RPC calls. - Evidence: Communicates with
azzle.orgAPIs to retrieve marketplace metadata and task listings. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the task marketplace, such as task descriptions and scopes.
- Ingestion points: Untrusted task metadata and off-chain messages (XMTP) are processed in
scripts/v2-lib.mjsand used to populate the agent's context. - Boundary markers:
SKILL.mdprovides explicit instructions to the agent to treat all marketplace data as untrusted and never to use it to authorize code execution or transactions. - Capability inventory: The skill has the ability to execute on-chain transactions and bounded approvals via the
bankrtool. - Sanitization: The skill implements a robust defense-in-depth strategy, requiring the agent to verify all contract addresses, runtime code hashes, and implementation code hashes against a reviewed 'pinned' configuration before every write.
- [COMMAND_EXECUTION]: The skill uses local shell scripts and CLI tools to verify blockchain state and execute transactions.
- Evidence: Executes
./scripts/v2-tasks.shto perform integrity checks on deployed contracts. - Evidence: Uses the
bankrCLI for wallet operations and transaction signing, with mandatory local decoding and user confirmation steps defined in the instructions.
Audit Metadata