neynar
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the Farcaster network (such as cast text, user bios, and search results) via the Neynar API. This data is ingested into the agent's context and could theoretically contain instructions designed to influence the agent's behavior.
- Ingestion points:
scripts/neynar.shfetches external content using the/feed,/search, and/castendpoints. - Boundary markers: The script returns data as JSON objects filtered by
jq, but does not wrap the natural language fields in explicit boundary markers or safety instructions. - Capability inventory: The skill utilizes
curlfor network requests toapi.neynar.comand reads its own configuration from~/.clawdbot/skills/neynar/config.json. - Sanitization: The script uses
jq -Rr @urito encode search queries and URL identifiers. However, other identifiers like usernames and FIDs are passed directly, which could allow for minor HTTP parameter injection if not validated by the agent. - [DATA_EXFILTRATION]: The skill transmits data to and from
api.neynar.comas part of its core functionality. - Evidence:
scripts/neynar.shusescurlto send API keys and user-provided cast content to the Neynar API base URL. - [COMMAND_EXECUTION]: The skill executes standard system utilities to perform its tasks.
- Evidence:
SKILL.mdandscripts/neynar.shrely oncurlfor network operations andjqfor robust JSON processing. - [SAFE]: The skill implements secret management best practices by instructing users to place sensitive API keys and signer UUIDs in a dedicated
config.jsonfile rather than hardcoding them in scripts. - [SAFE]: For write operations like posting or reacting, the script uses
jq --argto assemble JSON payloads, which prevents JSON injection attacks by ensuring all user input is properly escaped as string literals.
Audit Metadata