lienfi
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted marketplace data from the LienFi API while maintaining the capability to execute blockchain transactions.\n
- Ingestion points: The agent retrieves JSON data from
api.lienfi.comvia tools such assearch_liensandget_lienas described inSKILL.md.\n - Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instruction' warnings when processing the retrieved marketplace data.\n
- Capability inventory: The agent can request signatures (
/wallet/sign) and submit transactions (/wallet/submit) through the Bankr API, as outlined in the purchase lifecycle steps.\n - Sanitization: No explicit sanitization or validation of the remote marketplace content is mentioned before it is used to parameterize transactions.\n
- Mitigation: The skill enforces a mandatory human authorization step where the operator must sign a bearer token in a browser, which includes enforcing spend caps.\n- [COMMAND_EXECUTION]: The skill relies on shell commands for all network and service interactions.\n
- Details: The agent is instructed to use
curlto communicate withapi.lienfi.comandapi.bankr.bot. These operations are functional requirements for the skill's primary purpose and target either vendor-owned or service-specific domains.\n- [PRIVILEGE_ESCALATION]: The setup instructions require the operator to configure the wallet API key with broad permissions.\n - Details:
SKILL.mdandcatalog.jsonstate that theBANKR_API_KEYmust haveallowedRecipientsset to EMPTY andreadOnlyset to OFF. This configuration allows the agent to sign and submit transactions to any contract, which is a documented prerequisite for the agent's DeFi operations but represents a reduction in default security constraints.
Audit Metadata