skills/bankrbot/skills/yoink/Gen Agent Trust Hub

yoink

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Base blockchain, including addresses and timestamps.\n
  • Ingestion points: Contract queries for player addresses and scores in SKILL.md.\n
  • Boundary markers: No explicit delimiters or instructions are used to separate untrusted blockchain data from agent instructions.\n
  • Capability inventory: Transaction submission via the Bankr tool.\n
  • Sanitization: No sanitization is performed on data retrieved from the blockchain.\n- [EXTERNAL_DOWNLOADS]: The skill references the vendor's repository (github.com/BankrBot/skills) and a third-party repository (github.com/horsefacts/yoink-contracts) for code and installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — yoink