verona-asset

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill interacts with the local environment by executing the verona-toolkit CLI. Scripts such as create.sh, mint.sh, and predict.sh utilize array-based command construction (CMD+=(...)) and expansion ("${CMD[@]}") to ensure that user-provided arguments are handled safely without risk of command injection.
  • [SAFE]: Analysis of the 15 files reveals no evidence of prompt injection, data exfiltration, or persistence mechanisms. The skill's functionality aligns with its stated purpose of blockchain asset management, and the use of the burnt-labs vendor resources is consistent with the skill's authorship.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 02:30 PM
Security Audit — agent-trust-hub — verona-asset