quicknode
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external blockchain networks, which acts as an untrusted data source.
- Ingestion points: The skill retrieves JSON-RPC responses, gRPC stream data, and REST API results from Quicknode endpoints across multiple blockchains (Ethereum, Solana, Bitcoin, etc.) as seen in SKILL.md and various reference files.
- Boundary markers: The documentation does not provide specific instructions for the agent to use boundary markers or delimiters to isolate untrusted blockchain data from instruction context.
- Capability inventory: The skill is primarily read-only for blockchain data, but the documentation in SKILL.md and references/x402-reference.md demonstrates how to initialize wallet clients which could perform signing operations if a private key is provided to the agent's environment.
- Sanitization: There are no instructions for sanitizing or validating the contents of blockchain transactions, logs, or metadata before the agent processes them.
Audit Metadata