echidna
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The file
references/features-ffi-cheatcodes.mdprovides instructions on enabling the HEVM Foreign Function Interface (allowFFI: true). This feature allows fuzzed Ethereum smart contracts to execute arbitrary shell commands or external binaries on the host system. While intended for advanced testing, it introduces a potential remote code execution vector if the tool is used on malicious contract code. - [COMMAND_EXECUTION]: The skill references the execution of build and profiling commands such as
nix develop,cabal run, andechidnawithin thereferences/advanced-debugging.mdandreferences/core-cli.mdfiles. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process and fuzz Solidity source code provided as input. This creates a vulnerability surface where a malicious Solidity contract could include patterns aimed at influencing the AI agent's behavior during the analysis of test results.
- Ingestion points: Solidity source files (.sol) and project configuration files.
- Boundary markers: None identified in the provided instructions.
- Capability inventory: Execution of fuzzer commands and interaction with project build systems.
- Sanitization: No input validation or output filtering for the fuzzed contract content is mentioned.
Audit Metadata