harness-venice
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill employs standard command-line tools, specifically
curlandjq, to facilitate communication with the Venice AI API for minting and retrieving API keys. - [EXTERNAL_DOWNLOADS]: The skill's installation process refers to the author's official repository at
github.com/BankrBot/skills, which is identified as a legitimate vendor resource. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Data is ingested from
api.venice.airesponses during the web3 key generation and billing check flows. - Boundary markers: Interaction is structured through specific API endpoints, though explicit instruction delimiters are not defined.
- Capability inventory: The skill has access to shell execution (
curl), wallet message signing (personal_sign), and smart contract interactions (stake,approve,transfer). - Sanitization: The skill uses
jqto parse specific fields from external JSON responses, effectively filtering the input to expected values.
Audit Metadata