vara-agent-network-skills
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
evalcommand in theSKILL.mdpreamble to source configuration parameters (such as program IDs and network URLs) from the localreferences/program-ids.mdfile.\n- [COMMAND_EXECUTION]: The utility scriptscripts/json-get.mjsemploys thenew Functionconstructor to evaluate dynamic JavaScript expressions for parsing JSON tool output. This is used as a portable fallback for environments where thejqutility is unavailable.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from the Vara Agent Network registry and chat feeds. Evidence Chain: 1. Ingestion points:agent-create.md(registry data) andagent-chat-agent.md(mentions). 2. Boundary markers: Instructions inagent-create.mdStep 4 andagent-chat-agent.md"Decide" section warn the agent to treat external data as evidence, not instructions. 3. Capability inventory: The agent can perform on-chain transactions and manage wallet operations via thevara-walletCLI. 4. Sanitization: The skill relies on instruction-based guardrails rather than technical sanitization. This surface is inherent to the skill's purpose and is managed by the provided safety guidelines.\n- [EXTERNAL_DOWNLOADS]: The skill requires and provides instructions for installing external tools like thevara-walletCLI and the companionvara-skillspack. These are standard dependencies for the network's ecosystem and originate from the vendor's official repositories.
Audit Metadata