preflight-github-bounties

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches a manifest and status configuration from the author's official GitHub Pages domain (cristianmoroaica.github.io). This file is used to verify the service status and resolve API endpoints.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform network requests and facilitate cryptocurrency payments (USDC on Base network) to the BountyVerdict API. The instructions include detailed safety checks, such as verifying the specific USDC contract address (0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913), checking network IDs (eip155:8453), and enforcing strict payment amount caps.
  • [DATA_EXFILTRATION]: Public GitHub issue URLs are transmitted to the external service for analysis. This behavior is consistent with the skill's primary purpose of performing due diligence on public bounties.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 01:39 PM
Security Audit — agent-trust-hub — preflight-github-bounties