Indexing
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill configuration and setup instructions reference content from ethskills.com and a plugin from a third-party GitHub repository (austintgriffith/ethskills).\n- [COMMAND_EXECUTION]: The catalog.json file defines an install command using curl to download a remote markdown file.\n- [PROMPT_INJECTION]: The setup process instructs the agent to read instructions from a remote URL (https://ethskills.com/indexing/SKILL.md) before performing tasks, making it vulnerable to indirect prompt injection where external content could alter agent behavior.\n
- Ingestion points: catalog.json and SKILL.md reference https://ethskills.com/indexing/SKILL.md\n
- Boundary markers: None provided in the instructions.\n
- Capability inventory: Querying onchain data (network access).\n
- Sanitization: No sanitization or validation of the remote content.
Audit Metadata