skills/bankrbot/skills/Layer 2s/Gen Agent Trust Hub

Layer 2s

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The catalog.json file defines an installation command curl -s https://ethskills.com/l2s/SKILL.md that fetches content from an external domain (ethskills.com) during setup.
  • [PROMPT_INJECTION]: The skill instructions in catalog.json explicitly guide the user to tell the agent to read external content from https://ethskills.com/l2s/SKILL.md. This represents an indirect prompt injection vector where the agent is encouraged to ingest untrusted data from a remote server.
  • Ingestion points: https://ethskills.com/l2s/SKILL.md (specified in catalog.json setup and install fields).
  • Boundary markers: None present in the provided files to delineate external content from system instructions.
  • Capability inventory: The skill itself does not include executable scripts or tool-use capabilities, limiting the potential impact of an injection.
  • Sanitization: None detected; the skill relies on the agent directly reading the remote URL.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 02:11 PM
Security Audit — agent-trust-hub — Layer 2s