skills/bankrbot/skills/symbiosis/Gen Agent Trust Hub

symbiosis

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The script scripts/symbiosis-swap.py reads the user's Bankr API key from the local configuration file at ~/.bankr/config.json. This key is used to authenticate requests to the vendor's API at https://api.bankr.bot to submit blockchain transactions.
  • Evidence: config_path = os.environ.get("BANKR_CONFIG", os.path.expanduser("~/.bankr/config.json")) in scripts/symbiosis-swap.py.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data such as token addresses, chain IDs, and amounts, which serves as a potential attack surface for indirect prompt injection if malicious data is processed.
  • Ingestion points: Source and destination chain IDs, token contract addresses, and swap amounts are extracted from user prompts (e.g., in SKILL.md) and passed as command-line arguments to the execution scripts.
  • Boundary markers: The scripts do not implement explicit boundary markers or "ignore instructions" delimiters for the interpolated user values.
  • Capability inventory: The skill has the capability to fetch executable transaction data from Symbiosis Finance and submit transactions (approvals and swaps) via the Bankr Submit API.
  • Sanitization: The Python scripts perform basic type validation (e.g., int() for chain IDs and float() for amounts) but primarily rely on downstream API validation for the sanity of blockchain addresses and transaction parameters.
  • [COMMAND_EXECUTION]: The skill relies on local Python scripts (scripts/symbiosis-quote.py and scripts/symbiosis-swap.py) to perform its primary functions, including API interaction and transaction preparation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — symbiosis