skills/bankrbot/skills/clanker/Gen Agent Trust Hub

clanker

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the clanker-sdk, viem, and @openzeppelin/merkle-tree packages from the official NPM registry to facilitate blockchain interactions and Merkle tree generation.
  • [COMMAND_EXECUTION]: Documentation provides standard package manager commands (npm, yarn, pnpm) for installing the necessary software dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill documentation includes an indirect prompt injection surface as it defines parameters for user-provided data that are later processed by the agent.
  • Ingestion points: The clanker.deploy configuration accepts user-supplied strings for token metadata including name, symbol, and description as seen in SKILL.md and references/deployment.md.
  • Boundary markers: The skill does not provide specific instructions or delimiters to the agent to prevent it from executing commands that might be hidden within this metadata.
  • Capability inventory: The skill enables the agent to execute financial transactions on-chain and perform local file system writes (e.g., fs.writeFileSync in references/airdrops.md).
  • Sanitization: No sanitization or validation protocols for user-provided strings are described in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — clanker