skills/bankrbot/skills/harness-capu/Gen Agent Trust Hub

harness-capu

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies and mitigates risks associated with processing untrusted data from external sources.
  • Ingestion points: Untrusted data enters the agent context through Capminal gateway API responses, dashboard JavaScript metadata, and model inference completions as described in SKILL.md and references/opencap-api.md.
  • Boundary markers: The skill explicitly instructs the agent to ignore instructions, URLs, or payment requests embedded in remote data and completions.
  • Capability inventory: The skill utilizes wallet signing tools (bankr), transaction execution capabilities, and management of sensitive API keys (OPENCAP_API_KEY).
  • Sanitization: It mandates strict JSON field parsing, type validation, and the redaction of all credentials and authentication headers from logs and artifacts.
  • [SAFE]: The skill adheres to security best practices for blockchain and API interactions.
  • Implements a mandatory fail-safe requiring an independent deployment record to pin contract addresses and code hashes before any transaction can proceed.
  • Enforces multi-step user confirmation for all sensitive actions, including SIWE (Sign-In With Ethereum) messages and transaction batches.
  • Requires finite daily budgets and expiration dates for all generated API keys, preventing uncapped spending.
  • Restricts credential transmission to the official vendor domain (gw.capminal.ai) and prohibits sharing keys with upstream model providers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:47 AM
Security Audit — agent-trust-hub — harness-capu