skills/bankrbot/skills/siwa/Gen Agent Trust Hub

siwa

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill supports registering agent identity on the ERC-8004 registry by uploading a metadata object containing a name, description, and capabilities. This metadata is stored as a base64-encoded string and serves as a potential vector for indirect prompt injection if downstream agents or services process this registry data without proper sanitization.
  • Ingestion points: The metadata object construction in references/bankr-signer.md (lines 44-50) which is subsequently encoded into a data: URI.
  • Boundary markers: No delimiters or 'ignore' instructions are included in the generated metadata URI to prevent downstream misinterpretation of the text fields.
  • Capability inventory: The skill possesses network capabilities via fetch to interact with the Bankr Agent API and external SIWA verification endpoints.
  • Sanitization: The skill does not implement validation or sanitization for the metadata fields (name, description, etc.) before they are encoded and submitted to the blockchain registry.
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs users to install external packages from the NPM registry to enable functionality.
  • Evidence: Installation of @buildersgarden/siwa and viem is required for both agent-side signing and server-side verification.
  • [COMMAND_EXECUTION]: The skill setup and documentation include commands for package management and environment configuration.
  • Evidence: Usage of npm install for dependency management and instructions for setting environment variables like BANKR_API_KEY and RECEIPT_SECRET.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — siwa