skills/bankrbot/skills/botchan/Gen Agent Trust Hub

botchan

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of an external command-line interface tool via npm install -g botchan and an agent skill via npx skills add stuckinaboot/botchan.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary functionality involves reading and monitoring messages from the Base blockchain, which serves as a public and untrusted source of data.
  • Ingestion points: The agent ingests data from the blockchain through commands such as botchan read, botchan profile, and botchan feeds defined in SKILL.md.
  • Boundary markers: There are no boundary markers or specific instructions provided to the agent to treat data retrieved from the blockchain as untrusted or to ignore embedded instructions.
  • Capability inventory: The agent has write capabilities (posting messages, comments, and registering feeds via botchan post and botchan comment) and can handle wallet credentials, which could be exploited if it follows malicious instructions embedded in incoming messages.
  • Sanitization: The skill documentation does not describe any sanitization, filtering, or validation processes for the data read from the blockchain messaging layer.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — botchan