skills/bankrbot/skills/veil/Gen Agent Trust Hub

veil

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation suggests installing the @veil-cash/sdk via NPM or cloning from the official GitHub repository. These sources are project-specific and necessary for the skill's operation.\n- [COMMAND_EXECUTION]: The skill makes extensive use of Bash scripts to wrap CLI commands, which is the primary intended behavior for a wrapper skill.\n- [DATA_EXFILTRATION]: Network operations via curl target api.bankr.bot to facilitate transaction signing and job polling. These communications are part of the core functionality provided by the skill author's infrastructure.\n- [DYNAMIC_EXECUTION]: The skill executes a local SDK entry point (dist/cli/index.cjs) using node. This dynamic loading is a standard requirement for running the built SDK from source.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes user input and transaction data to build prompts for the Bankr agent.\n
  • Ingestion points: User-provided strings in veil-bankr-prompt.sh and transaction JSON in veil-bankr-submit-tx.sh.\n
  • Boundary markers: No explicit delimitation or 'ignore instructions' markers are used when embedding data into prompts.\n
  • Capability inventory: The skill has access to the network, local file system, and shell execution.\n
  • Sanitization: Standard jq filtering is used to ensure data structure, but no content-based sanitization for injection patterns is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — veil