symbiosis
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The script
scripts/symbiosis-swap.pyreads the user's Bankr API key from the local configuration file at~/.bankr/config.json. This key is used to authenticate requests to the vendor's API athttps://api.bankr.botto submit blockchain transactions. - Evidence:
config_path = os.environ.get("BANKR_CONFIG", os.path.expanduser("~/.bankr/config.json"))inscripts/symbiosis-swap.py. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data such as token addresses, chain IDs, and amounts, which serves as a potential attack surface for indirect prompt injection if malicious data is processed.
- Ingestion points: Source and destination chain IDs, token contract addresses, and swap amounts are extracted from user prompts (e.g., in
SKILL.md) and passed as command-line arguments to the execution scripts. - Boundary markers: The scripts do not implement explicit boundary markers or "ignore instructions" delimiters for the interpolated user values.
- Capability inventory: The skill has the capability to fetch executable transaction data from Symbiosis Finance and submit transactions (approvals and swaps) via the Bankr Submit API.
- Sanitization: The Python scripts perform basic type validation (e.g.,
int()for chain IDs andfloat()for amounts) but primarily rely on downstream API validation for the sanity of blockchain addresses and transaction parameters. - [COMMAND_EXECUTION]: The skill relies on local Python scripts (
scripts/symbiosis-quote.pyandscripts/symbiosis-swap.py) to perform its primary functions, including API interaction and transaction preparation.
Audit Metadata