bitvm
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, specifically Bitcoin header and transaction information, which creates a surface for indirect prompt injection if an agent is directed to act based on the content or processed results of these inputs.
- Ingestion points: Bitcoin header chain binary files downloaded from an external source (zerosync.org) and transaction identifiers/data provided via CLI arguments in
references/features-header-chain.mdandreferences/features-bridge-cli.md. - Boundary markers: None present; the skill lacks instructions to isolate or delimit untrusted external data from the agent's reasoning context.
- Capability inventory: The skill utilizes shell execution for the
bridgeandproverbinaries, which are capable of broadcasting transactions to the Bitcoin network and interacting with the local filesystem. - Sanitization: While the skill employs cryptographic verification (Taproot scripts and Risc0 circuits) to ensure the technical integrity of the data, it does not include sanitization to prevent adversarial instructions embedded in the data from influencing agent behavior.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading data from an external, non-whitelisted third-party domain.
- Evidence:
wget https://zerosync.org/chaindata/headers.bininreferences/features-header-chain.md. - [COMMAND_EXECUTION]: The skill documentation describes the execution of shell commands for local binaries using sensitive arguments such as private keys and transaction IDs.
- Evidence: Subcommands documented in
references/features-bridge-cli.md(e.g.,bridge keys -d <SECRET_KEY>) and build/execution steps for theproverinreferences/features-header-chain.md.
Audit Metadata