skills/bankrbot/skills/stakr-protocol/Gen Agent Trust Hub

stakr-protocol

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation for smart contract interactions on the Base blockchain. The contract addresses provided (e.g., StakrVaultFactory at 0x7Ef55108fa37472296DA59D2287FdA92cd21A0d0) are public and consistent with the protocol's deployment. No hardcoded secrets or sensitive credentials were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided parameters such as vault addresses, token amounts, and timing settings to formulate natural-language prompts for the 'bankr' agent. While this represents a data ingestion surface, the risk is considered low as the input is limited to specific transaction parameters within the DeFi protocol's context. Boundary markers are not explicitly mentioned in the skill text, but sanitization is typically handled by the underlying execution environment (bankr).
  • [EXTERNAL_DOWNLOADS]: The skill references its source repository on GitHub (github.com/BankrBot/skills). This is a legitimate vendor resource belonging to the skill's author, used for installation and versioning.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:44 AM
Security Audit — agent-trust-hub — stakr-protocol