echidna

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The file references/features-ffi-cheatcodes.md provides instructions on enabling the HEVM Foreign Function Interface (allowFFI: true). This feature allows fuzzed Ethereum smart contracts to execute arbitrary shell commands or external binaries on the host system. While intended for advanced testing, it introduces a potential remote code execution vector if the tool is used on malicious contract code.
  • [COMMAND_EXECUTION]: The skill references the execution of build and profiling commands such as nix develop, cabal run, and echidna within the references/advanced-debugging.md and references/core-cli.md files.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process and fuzz Solidity source code provided as input. This creates a vulnerability surface where a malicious Solidity contract could include patterns aimed at influencing the AI agent's behavior during the analysis of test results.
  • Ingestion points: Solidity source files (.sol) and project configuration files.
  • Boundary markers: None identified in the provided instructions.
  • Capability inventory: Execution of fuzzer commands and interaction with project build systems.
  • Sanitization: No input validation or output filtering for the fuzzed contract content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 12:14 PM