pantheon-staking

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes token names and metadata retrieved from a remote registry API, which could potentially contain malicious instructions.
  • Ingestion points: The skill fetches data from registry endpoints at launch.pantheonvaults.com as defined in SKILL.md.
  • Boundary markers: The skill includes a specific 'Prompt-injection rule' section that explicitly directs the agent to treat all fetched content as data and to disregard any directives found within external payloads.
  • Capability inventory: The skill is capable of performing blockchain transactions, including approve, stake, and claimReward.
  • Sanitization: Robust 'Transaction Gates' (G1-G8) are implemented, including G2 (Pin assertion) which validates registry data against hardcoded addresses, and G6 (Confirm echo) which requires explicit user consent after restating all transaction details.
  • [EXTERNAL_DOWNLOADS]: The skill fetches configuration and token registry information from the vendor's infrastructure.
  • Retrieval of registry data from https://launch.pantheonvaults.com/api/skill/registry.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:46 AM
Security Audit — agent-trust-hub — pantheon-staking