skills/bankrbot/skills/voidly-pay/Gen Agent Trust Hub

voidly-pay

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external provider manifests and blockchain transaction receipts. Analysis shows strong defensive measures are in place to mitigate potential injection risks. \n
  • Ingestion points: External data enters the context via provider manifests (scripts/discover.mjs) and blockchain RPC responses (scripts/verify-settlement.mjs). \n
  • Boundary markers: The skill includes explicit instructions in SKILL.md for the agent to treat all external data as untrusted information rather than executable instructions. \n
  • Capability inventory: The skill is limited to read-only network queries and local file operations. It does not provide capabilities for arbitrary command execution or unauthorized data transmission. \n
  • Sanitization: A robust 'quoted()' utility in scripts/lib/pins.mjs escapes control characters and line separators to prevent context manipulation. Additionally, scripts/lib/pins.mjs implements a 'usableArgValue' filter that rejects steganographic and homoglyph characters in input fields. \n- [SAFE]: The skill uses established, version-pinned dependencies for cryptography and blockchain interaction (ethers, tweetnacl). All network communication targets specific, allowlisted providers and public blockchain RPC endpoints. \n- [SAFE]: Sensitive local files (identities and session keys) are protected using restrictive POSIX permissions (0600) and verified through opened file descriptors to prevent symlink or race condition attacks. \n- [SAFE]: Static analysis findings regarding hidden Unicode characters in tests/seal-hire.test.mjs are confirmed to be benign test cases designed to verify the skill's own character-filtering mitigations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:47 AM
Security Audit — agent-trust-hub — voidly-pay