battlechain-tutorial
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses the
Globtool to perform a read-only scan of the project's source code and existing scripts. This data ingestion is restricted to the local workspace and is used solely to provide context for script generation. - [SAFE]: The generated code relies on the
cyfrin/battlechain-liblibrary. This is an expected dependency given the skill's authorship and its focus on the BattleChain ecosystem. - [SAFE]: The skill does not execute any shell commands or perform network operations autonomously. It provides the user with generated scripts and deployment instructions for manual verification and execution using standard blockchain development tools like
forgeandcast. - [SAFE]: No patterns of prompt injection, data exfiltration, or obfuscation were identified. The use of interactive questions through the
AskUserQuestiontool ensures a structured and transparent interaction with the user. - [SAFE]: While the skill processes user-provided contract files (Category 8 surface), the risk of indirect prompt injection is mitigated by the highly structured script generation templates and the mandatory phase of manual user review before execution.
Audit Metadata