skills/bankrbot/skills/endaoment/Gen Agent Trust Hub

endaoment

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The search functionality in scripts/search.sh fetches charity metadata (names, descriptions) from an external API (api.endaoment.org) and displays it to the agent. This untrusted data could potentially contain malicious instructions.
  • Ingestion points: scripts/search.sh API responses.
  • Boundary markers: None identified.
  • Capability inventory: The skill can execute blockchain transactions via bankr agent in scripts/donate.sh.
  • Sanitization: The description field is truncated to 200 characters, reducing the available surface for long-form injection attacks.
  • [COMMAND_EXECUTION]: The scripts/donate.sh script dynamically generates transaction data and instructs the agent to execute it using the bankr agent command. While this is the primary intended function of the skill, it represents a high-privilege interaction where the script controls the agent's blockchain activity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — endaoment