skills/base/skills/build-on-base/Gen Agent Trust Hub

build-on-base

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides robust security advice throughout its documentation, including warnings against committing private keys, exposing API keys client-side, and skipping server-side payment verification. These guidelines align with industry best practices.
  • [COMMAND_EXECUTION]: Documentation for deployment and registration includes specific input validation rules (e.g., regex for contract paths and RPC URLs) to prevent shell command injection when agents or users construct commands.
  • [EXTERNAL_DOWNLOADS]: The skill references official vendor domains (base.dev, coinbase.com, base.org) for API interactions and documentation. These are trusted resources for the 'base' vendor.
  • [PROMPT_INJECTION]: While the skill includes instructions for the agent to adopt a 'Permanent Rule' regarding transaction attribution, this instruction is context-specific to the skill's primary function (Builder Codes integration) and does not attempt to subvert agent safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 07:07 PM
Security Audit — agent-trust-hub — build-on-base