eips
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the
eipwvalidation tool using the Rust package manager viacargo install eipw. This is a standard procedure for authors within the Ethereum development community to ensure their proposals meet structural requirements. - [COMMAND_EXECUTION]: The documentation includes examples of running the
eipwcommand-line tool to validate local EIP files against the official specification. These commands are intended for development and quality assurance purposes. - [INDIRECT_PROMPT_INJECTION]: The skill describes how an agent should process and reference EIP documents, which are external files formatted in Markdown and YAML. This ingestion of third-party content represents a standard attack surface for indirect prompt injection if the source files are untrusted.
- Ingestion points: The agent is directed to read and resolve EIP specifications from the
sources/eips/EIPS/directory. - Boundary markers: No specific delimiters or instructions to ignore embedded commands within the EIP files are provided in the skill instructions.
- Capability inventory: The skill references the ability to execute the
eipwtool for file validation. - Sanitization: The skill relies on the
eipwtool for structural validation but does not describe methods for sanitizing the semantic content of proposals against adversarial instructions.
Audit Metadata