cattown
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill makes frequent requests to 'api.cat.town' to retrieve the game's item catalog, staking leaderboards, user deposit history, and gacha results. These network operations are directed at a domain that is not included in the default whitelisted services for data exfiltration analysis.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could be influenced by an attacker to manipulate the agent's behavior. For instance, item names or flavor text in the public catalog could contain malicious instructions.
- Ingestion points: Data is ingested from multiple endpoints on 'api.cat.town', such as '/v2/items/master' and '/v2/revenue/staking/leaderboard'.
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when the agent interprets this external data.
- Capability inventory: The agent has the capability to build and submit significant blockchain transactions, including KIBBLE staking, gacha capsule purchases, and batch selling of NFTs.
- Sanitization: The skill provides logic for data normalization (e.g., mapping contract enums to API strings) but does not include explicit sanitization or filtering of text fields to prevent injection attacks.
Audit Metadata