token-scam-analysis
Warn
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The skill instructs the agent to dynamically generate and execute JavaScript files (
analyze.mjs) using theviemlibrary to perform batch on-chain reads and concentration analysis. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources such as blockchain contract ABIs, social media (X/Twitter), search engine results, and project documentation (Gitbook). The analysis lacks explicit boundary markers or sanitization logic when processing these inputs in
SKILL.md, which are then used to influence the agent's forensic verdict and report generation. The skill possesses extensive capabilities including script execution viaexecute_cli, file writing to/reports/, and network operations viabrowse_url. - [COMMAND_EXECUTION]: The skill utilizes
execute_clito install dependencies and run locally generated analysis scripts for processing blockchain data. - [EXTERNAL_DOWNLOADS]: The skill fetches data from well-known services including GitHub, Etherscan, and Basescan, and installs the
viemlibrary from the official npm registry.
Audit Metadata