zyfai
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as wallet addresses and DeFi protocol information, which presents a surface for indirect instructions.
- Ingestion points: SDK methods in SKILL.md accept userAddress, amount, and chainId from the agent's context, and process responses from the Zyfai API.
- Boundary markers: No specific delimiters or "ignore" instructions for external data are included in the documentation snippets.
- Capability inventory: The skill is capable of initiating blockchain transactions (deploy, deposit, withdraw) and making authenticated network requests to the vendor's API at sdk.zyf.ai.
- Sanitization: The skill relies on standard web3 libraries like viem and the @zyfai/sdk for parameter validation, though explicit sanitization is not shown in the documentation examples.
Audit Metadata