voidly-pay
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external provider manifests and blockchain transaction receipts. Analysis shows strong defensive measures are in place to mitigate potential injection risks. \n
- Ingestion points: External data enters the context via provider manifests (scripts/discover.mjs) and blockchain RPC responses (scripts/verify-settlement.mjs). \n
- Boundary markers: The skill includes explicit instructions in SKILL.md for the agent to treat all external data as untrusted information rather than executable instructions. \n
- Capability inventory: The skill is limited to read-only network queries and local file operations. It does not provide capabilities for arbitrary command execution or unauthorized data transmission. \n
- Sanitization: A robust 'quoted()' utility in scripts/lib/pins.mjs escapes control characters and line separators to prevent context manipulation. Additionally, scripts/lib/pins.mjs implements a 'usableArgValue' filter that rejects steganographic and homoglyph characters in input fields. \n- [SAFE]: The skill uses established, version-pinned dependencies for cryptography and blockchain interaction (ethers, tweetnacl). All network communication targets specific, allowlisted providers and public blockchain RPC endpoints. \n- [SAFE]: Sensitive local files (identities and session keys) are protected using restrictive POSIX permissions (0600) and verified through opened file descriptors to prevent symlink or race condition attacks. \n- [SAFE]: Static analysis findings regarding hidden Unicode characters in tests/seal-hire.test.mjs are confirmed to be benign test cases designed to verify the skill's own character-filtering mitigations.
Audit Metadata