bankr
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill presents a significant attack surface for indirect prompt injection by combining powerful financial and system capabilities with the ingestion of untrusted external data.
- Ingestion points: The agent ingests data from user-supplied prompts, social media handle resolution (Twitter, Farcaster), and external web content through a built-in headless browser.
- Boundary markers: The documentation does not describe explicit use of prompt delimiters or specific instructions to ignore embedded commands when processing content from the headless browser or social metadata.
- Capability inventory: The skill possesses extensive capabilities across multiple chains, including token swaps, multi-recipient transfers, raw transaction submission with arbitrary calldata, and persistent file storage operations.
- Sanitization: Safety controls are implemented at the wallet level, including default $500 daily and per-transaction spending limits, a 15% price impact limit, and mandatory location verification for trading tokenized equities.
- [DYNAMIC_EXECUTION]: The skill enables the agent to generate and deploy executable code at runtime.
- The x402 Cloud feature allows the agent to write handler code for paid API endpoints and deploy them directly to the x402 cloud infrastructure.
- This involves the dynamic generation of script content based on user requirements and its subsequent execution or deployment in a remote environment.
Audit Metadata