avail
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent on how to build and execute the Avail node binary using common developer tools.
- Evidence: Commands for building the project using
cargo run --locked --releaseare provided inreferences/core-node-and-chains.md. - Evidence: Instructions for running the node in a containerized environment using
docker runwith volume mounting and network port exposure are documented inreferences/core-node-and-chains.md. - [INDIRECT_PROMPT_INJECTION]: The skill describes functionality for ingesting and processing data from an external, untrusted source (the Avail blockchain), which creates a potential surface for indirect prompt injection attacks.
- Ingestion points: Data is ingested via various Kate RPC methods such as
kate_queryRows,kate_queryProof,kate_queryMultiProof, andkate_queryDataProofas described inreferences/core-kate-rpc.md. - Boundary markers: No specific boundary markers or "ignore embedded instructions" warnings are included in the instructions for handling the data returned by these RPC calls.
- Capability inventory: The node binary, when running, has the capability to perform network operations and local filesystem writes (to the specified data directory).
- Sanitization: The skill does not provide specific instructions for sanitizing or validating the content retrieved from the blockchain before the agent processes it.
Audit Metadata