skills/dfinity/icskills/ckbtc/Gen Agent Trust Hub

ckbtc

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides integration instructions and code snippets for interacting with official Chain-Key Bitcoin (ckBTC) canisters managed by DFINITY. All referenced canister IDs, such as mxzaz-hqaaa-aaaar-qaada-cai (Ledger) and mqygn-kiaaa-aaaar-qaadq-cai (Minter), are legitimate public identifiers for the Internet Computer mainnet infrastructure. All referenced libraries (e.g., ic-cdk, icrc-ledger-types, mops) are standard for this ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as Bitcoin addresses and transaction amounts, which represents a standard attack surface for indirect prompt injection.
  • Ingestion points: The withdraw functions in src/backend/main.mo and src/lib.rs accept a btcAddress string from the user context or input.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the example integration code.
  • Capability inventory: The skill enables the agent to perform sensitive financial operations, including remote canister calls for icrc1_transfer, icrc2_approve, and retrieve_btc_with_approval to move ckBTC and Bitcoin.
  • Sanitization: The skill relies on the Internet Computer's Candid interface for strong type checking and serialization. Actual validation of the Bitcoin address format is performed by the remote Minter canister's logic rather than the skill's code itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:49 PM
Security Audit — agent-trust-hub — ckbtc