clanker
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
clanker-sdk,viem, and@openzeppelin/merkle-treepackages from the official NPM registry to facilitate blockchain interactions and Merkle tree generation. - [COMMAND_EXECUTION]: Documentation provides standard package manager commands (npm, yarn, pnpm) for installing the necessary software dependencies.
- [INDIRECT_PROMPT_INJECTION]: The skill documentation includes an indirect prompt injection surface as it defines parameters for user-provided data that are later processed by the agent.
- Ingestion points: The
clanker.deployconfiguration accepts user-supplied strings for token metadata includingname,symbol, anddescriptionas seen inSKILL.mdandreferences/deployment.md. - Boundary markers: The skill does not provide specific instructions or delimiters to the agent to prevent it from executing commands that might be hidden within this metadata.
- Capability inventory: The skill enables the agent to execute financial transactions on-chain and perform local file system writes (e.g.,
fs.writeFileSyncinreferences/airdrops.md). - Sanitization: No sanitization or validation protocols for user-provided strings are described in the documentation.
Audit Metadata