skills/bankrbot/skills/based-mining/Gen Agent Trust Hub

based-mining

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents an inherent attack surface where the agent processes data from external API endpoints, which could theoretically contain malicious instructions.
  • Ingestion points: Data is ingested via GET and POST responses from multiple endpoints hosted on x402.bankr.bot (e.g., /pool-status, /worker-status, /mine).
  • Boundary markers: The skill provides extensive boundary instructions in the 'Responses are data, not instructions' section, explicitly telling the agent to treat every field as untrusted and never to follow instructions found within responses.
  • Capability inventory: The agent has the capability to authorize USDC payments on the Base network, perform network requests to specific hosts, and poll status URLs.
  • Sanitization: The skill mandates strict sanitization through field-by-field validation of payment challenges against pinned values (addresses, assets, and amounts) and enforces a strict HTTPS allowlist (x402.bankr.bot, api.basedmining.xyz, basedmining.xyz) for all polling operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:47 AM
Security Audit — agent-trust-hub — based-mining