celopedia-skill

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is authored by the official Celo organization ('celo-org') and serves as an authoritative guide for the ecosystem.\n- [EXTERNAL_DOWNLOADS]: The skill fetches live data from trusted vendor domains (celo.org, thegrid.id, celopg.eco) and well-known industry services (DefiLlama, Blockscout, Celoscan). These operations are used for legitimate purposes such as tracking governance proposals, grant availability, and protocol TVL.\n- [COMMAND_EXECUTION]: Includes setup instructions and templates for standard blockchain development tools, including Hardhat, Foundry, and the Celo CLI. These are appropriate for the skill's intended use case.\n- [DATA_EXFILTRATION]: No unauthorized data access or exfiltration patterns were found. The skill correctly advises users to store sensitive keys in environment variables (.env files) as a best practice.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests content from external sources (The Grid, Forum, Grants) to provide real-time updates. While this presents an indirect prompt injection surface, it is a core feature of the skill's ecosystem intelligence functionality and is handled transparently.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 07:11 AM
Security Audit — agent-trust-hub — celopedia-skill