foundry
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents how the agent should process and execute Solidity files, which serves as a surface for indirect prompt injection. Maliciously crafted contracts could contain instructions or cheatcodes designed to compromise the agent's environment.
- Ingestion points: Solidity source code and test files located in the project's
src/,test/, andscript/directories. - Boundary markers: The skill does not provide instructions for the agent to use delimiters or ignore instructions embedded within the processed Solidity code or comments.
- Capability inventory: The agent is taught to use tools that can execute arbitrary shell commands (
vm.ffi), perform network operations via RPC endpoints (cast,forge script), and write to the local filesystem (forge build). - Sanitization: There are no requirements or methods provided to sanitize or validate the Solidity source code before execution or analysis.
- [DYNAMIC_EXECUTION]: The documentation includes instructions for the
vm.fficheatcode, which enables the EVM to execute arbitrary external binaries and shell commands. This is a powerful feature that presents a dynamic execution risk if the commands or their arguments are influenced by untrusted source code. - [EXTERNAL_DOWNLOADS]: The skill describes using
npxto run the nightly version of the Chisel Solidity REPL (@foundry-rs/chisel@nightly), which involves downloading and executing code from the NPM registry. This represents a standard dependency acquisition for the toolset. - [COMMAND_EXECUTION]: The skill provides instructions for various CLI tools (
forge,cast,anvil,chisel) that involve subprocess execution and interaction with the operating system and network.
Audit Metadata