ckbtc
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides integration instructions and code snippets for interacting with official Chain-Key Bitcoin (ckBTC) canisters managed by DFINITY. All referenced canister IDs, such as
mxzaz-hqaaa-aaaar-qaada-cai(Ledger) andmqygn-kiaaa-aaaar-qaadq-cai(Minter), are legitimate public identifiers for the Internet Computer mainnet infrastructure. All referenced libraries (e.g.,ic-cdk,icrc-ledger-types,mops) are standard for this ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as Bitcoin addresses and transaction amounts, which represents a standard attack surface for indirect prompt injection.
- Ingestion points: The
withdrawfunctions insrc/backend/main.moandsrc/lib.rsaccept abtcAddressstring from the user context or input. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the example integration code.
- Capability inventory: The skill enables the agent to perform sensitive financial operations, including remote canister calls for
icrc1_transfer,icrc2_approve, andretrieve_btc_with_approvalto move ckBTC and Bitcoin. - Sanitization: The skill relies on the Internet Computer's Candid interface for strong type checking and serialization. Actual validation of the Bitcoin address format is performed by the remote Minter canister's logic rather than the skill's code itself.
Audit Metadata