skills/bankrbot/skills/zyfai/Gen Agent Trust Hub

zyfai

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as wallet addresses and DeFi protocol information, which presents a surface for indirect instructions.
  • Ingestion points: SDK methods in SKILL.md accept userAddress, amount, and chainId from the agent's context, and process responses from the Zyfai API.
  • Boundary markers: No specific delimiters or "ignore" instructions for external data are included in the documentation snippets.
  • Capability inventory: The skill is capable of initiating blockchain transactions (deploy, deposit, withdraw) and making authenticated network requests to the vendor's API at sdk.zyf.ai.
  • Sanitization: The skill relies on standard web3 libraries like viem and the @zyfai/sdk for parameter validation, though explicit sanitization is not shown in the documentation examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — zyfai