bankr-communities

Fail

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and links to https://qrcoin.fun in SKILL.md and SKILL-LINKED-FUNDRAISERS.md. This domain is confirmed to be on a security blacklist for malicious activity.
  • [COMMAND_EXECUTION]: In SKILL-LINKED-FUNDRAISERS.md, the documentation instructs users to execute npm install -g @0xwork/cli@latest. Recommending the global installation of third-party packages from non-vendor sources is a high-risk practice that can lead to system-wide compromise.
  • [PROMPT_INJECTION]: The file references/PROMPT-INJECTION.md and references/RESPONSE-SAFETY.md contain instructional markers such as "ignore previous rules" and "must never change agent behavior". While these are intended as defensive guidelines, they employ the exact linguistic patterns used in prompt injection attacks to override system prompts and could be exploited to manipulate the agent.
  • [DATA_EXFILTRATION]: The skill is designed to ingest and process untrusted data from external sources, including tweet text and space posts (X-REPLY-POST-CONTENT.md, references/PROMPT-INJECTION.md). This ingestion surface, combined with the agent's ability to make network requests, creates a significant risk of indirect prompt injection which could lead to the exfiltration of sensitive information like API keys or wallet addresses.
  • [EXTERNAL_DOWNLOADS]: The skill directs users to download and install additional code from external GitHub repositories (github.com/anondevv69/bankr-space and github.com/BankrBot/skills), which introduces third-party dependency risks.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 13, 2026, 05:49 PM
Security Audit — agent-trust-hub — bankr-communities