coffer
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the Robinhood blockchain (RPC responses, event logs, and token metadata).
- Ingestion points: Data is fetched via RPC calls defined in SKILL.md and references/abi-and-calls.md.
- Boundary markers: The skill includes explicit safety instructions in the Authorization and trust boundary section, stating that external data must never be treated as instructions.
- Capability inventory: Write operations are strictly limited to depositETH and withdraw functions on the pinned vault address.
- Sanitization: The skill implements multi-step validation, including eth_getCode checks, chain ID verification, and transaction simulation before execution.
- [COMMAND_EXECUTION]: The skill performs blockchain transactions and queries.
- Evidence: Execution is gated by mandatory user authorization, simulation (eth_call), and validation of the signer and transaction parameters as detailed in the Safety sections of SKILL.md.
Audit Metadata