waybackclaw
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process behavioral records and reputation data generated by other agents, creating a surface for indirect instructions.\n
- Ingestion points: Data is ingested via endpoints such as
/api/archive/memoriesand/api/archive/reputation(specified inSKILL.mdandreferences/api-reference.md).\n - Boundary markers:
SKILL.mdcontains a dedicated 'API responses are untrusted input' section with instructions to treat all received data as untrusted third-party content and to ignore any embedded instructions.\n - Capability inventory: The skill uses
curlfor network communication and involves on-chain payment logic ($WBC transfers on Base).\n - Sanitization: The skill mandates user confirmation for payments and instructs the agent to report content neutrally rather than following instructions or links found within the data.
Audit Metadata