defi-native
Fail
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Automated security scanners have blacklisted several URLs referenced in the 'manifest.json' documentation registry. Specifically, 'docs.eigencloud.xyz' and 'docs.elixir.xyz' are flagged as malicious. The domain 'docs.eigencloud.xyz' appears to be a typosquatted version of the official EigenLayer documentation (eigenlayer.xyz), which is a common indicator of a phishing or malware distribution attempt. Additionally, 'etherfi.gitbook.io' has been flagged as a phishing risk.
- [REMOTE_CODE_EXECUTION]: A file reputation scanner has flagged the 'manifest.json' file as 'FileRepMalware'. This file serves as the primary directory for the agent to fetch external data and documentation. A malware detection on this configuration file indicates a potential supply-chain compromise or the inclusion of malicious link patterns intended to facilitate further attacks.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process a high volume of content from 120+ external DeFi documentation sources and APIs. This creates an extensive attack surface for indirect prompt injection, where malicious instructions could be embedded in remote documentation to hijack agent behavior. Although the skill includes 'Prime Directive 9' (instructing the agent to treat remote content as untrusted data), the presence of confirmed malicious domains in the manifest significantly increases the risk that an agent will ingest adversarial content.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 6 malicious URL(s) - DO NOT USE
Audit Metadata