siwa
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill supports registering agent identity on the ERC-8004 registry by uploading a metadata object containing a name, description, and capabilities. This metadata is stored as a base64-encoded string and serves as a potential vector for indirect prompt injection if downstream agents or services process this registry data without proper sanitization.
- Ingestion points: The
metadataobject construction inreferences/bankr-signer.md(lines 44-50) which is subsequently encoded into adata:URI. - Boundary markers: No delimiters or 'ignore' instructions are included in the generated metadata URI to prevent downstream misinterpretation of the text fields.
- Capability inventory: The skill possesses network capabilities via
fetchto interact with the Bankr Agent API and external SIWA verification endpoints. - Sanitization: The skill does not implement validation or sanitization for the metadata fields (
name,description, etc.) before they are encoded and submitted to the blockchain registry. - [EXTERNAL_DOWNLOADS]: The skill documentation instructs users to install external packages from the NPM registry to enable functionality.
- Evidence: Installation of
@buildersgarden/siwaandviemis required for both agent-side signing and server-side verification. - [COMMAND_EXECUTION]: The skill setup and documentation include commands for package management and environment configuration.
- Evidence: Usage of
npm installfor dependency management and instructions for setting environment variables likeBANKR_API_KEYandRECEIPT_SECRET.
Audit Metadata