token-scam-analysis

Warn

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill instructs the agent to dynamically generate and execute JavaScript files (analyze.mjs) using the viem library to perform batch on-chain reads and concentration analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources such as blockchain contract ABIs, social media (X/Twitter), search engine results, and project documentation (Gitbook). The analysis lacks explicit boundary markers or sanitization logic when processing these inputs in SKILL.md, which are then used to influence the agent's forensic verdict and report generation. The skill possesses extensive capabilities including script execution via execute_cli, file writing to /reports/, and network operations via browse_url.
  • [COMMAND_EXECUTION]: The skill utilizes execute_cli to install dependencies and run locally generated analysis scripts for processing blockchain data.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data from well-known services including GitHub, Etherscan, and Basescan, and installs the viem library from the official npm registry.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 24, 2026, 04:44 AM
Security Audit — agent-trust-hub — token-scam-analysis