multi-canister

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill documents the Canister Factory pattern for dynamic deployment of WASM modules via the management canister. It explicitly flags security risks associated with caller-supplied WASM and provides remediation guidance including module hashing and allowlisting.
  • [INDIRECT_PROMPT_INJECTION]: Analyzed the attack surface for untrusted data ingestion. 1. Ingestion points: The register and createPost methods in src/user_service/main.mo and src/content_service/main.mo ingest strings and principals. 2. Boundary markers: Uses principal-based authentication checks. 3. Capability inventory: Performs inter-canister calls and management canister operations for canister creation. 4. Sanitization: Documentation recommends explicit input validation, length limits, and character set enforcement.
  • [COMMAND_EXECUTION]: Employs standard icp-cli developer tools for canister deployment and environment variable management, which is consistent with the intended purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:49 PM
Security Audit — agent-trust-hub — multi-canister