endaoment
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The search functionality in
scripts/search.shfetches charity metadata (names, descriptions) from an external API (api.endaoment.org) and displays it to the agent. This untrusted data could potentially contain malicious instructions. - Ingestion points:
scripts/search.shAPI responses. - Boundary markers: None identified.
- Capability inventory: The skill can execute blockchain transactions via
bankr agentinscripts/donate.sh. - Sanitization: The
descriptionfield is truncated to 200 characters, reducing the available surface for long-form injection attacks. - [COMMAND_EXECUTION]: The
scripts/donate.shscript dynamically generates transaction data and instructs the agent to execute it using thebankr agentcommand. While this is the primary intended function of the skill, it represents a high-privilege interaction where the script controls the agent's blockchain activity.
Audit Metadata