juicebox-v6
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a mandatory 'review → re-verify → simulate → gas → send → prove' pipeline for all on-chain write operations to prevent blind signing and ensure transaction integrity.
- [SAFE]: Security guidelines for generated frontends include restrictive Content Security Policies and the use of exact, integrity-pinned local dependencies from official registries.
- [SAFE]: All external service interactions, including meta-transaction relays (Relayr) and indexers (Bendystraw), are treated as untrusted and require independent validation of blockchain state.
- [SAFE]: The instructions strictly prohibit the handling of private keys within the skill or generated code, instead relying on approved wallet signing flows.
- [SAFE]: Technical analysis of the utility scripts and wallet helpers found no evidence of malicious behavior, data exfiltration, or obfuscation.
Audit Metadata