pantheon-staking
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes token names and metadata retrieved from a remote registry API, which could potentially contain malicious instructions.
- Ingestion points: The skill fetches data from registry endpoints at
launch.pantheonvaults.comas defined inSKILL.md. - Boundary markers: The skill includes a specific 'Prompt-injection rule' section that explicitly directs the agent to treat all fetched content as data and to disregard any directives found within external payloads.
- Capability inventory: The skill is capable of performing blockchain transactions, including
approve,stake, andclaimReward. - Sanitization: Robust 'Transaction Gates' (G1-G8) are implemented, including G2 (Pin assertion) which validates registry data against hardcoded addresses, and G6 (Confirm echo) which requires explicit user consent after restating all transaction details.
- [EXTERNAL_DOWNLOADS]: The skill fetches configuration and token registry information from the vendor's infrastructure.
- Retrieval of registry data from
https://launch.pantheonvaults.com/api/skill/registry.
Audit Metadata