foundry

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents how the agent should process and execute Solidity files, which serves as a surface for indirect prompt injection. Maliciously crafted contracts could contain instructions or cheatcodes designed to compromise the agent's environment.
  • Ingestion points: Solidity source code and test files located in the project's src/, test/, and script/ directories.
  • Boundary markers: The skill does not provide instructions for the agent to use delimiters or ignore instructions embedded within the processed Solidity code or comments.
  • Capability inventory: The agent is taught to use tools that can execute arbitrary shell commands (vm.ffi), perform network operations via RPC endpoints (cast, forge script), and write to the local filesystem (forge build).
  • Sanitization: There are no requirements or methods provided to sanitize or validate the Solidity source code before execution or analysis.
  • [DYNAMIC_EXECUTION]: The documentation includes instructions for the vm.ffi cheatcode, which enables the EVM to execute arbitrary external binaries and shell commands. This is a powerful feature that presents a dynamic execution risk if the commands or their arguments are influenced by untrusted source code.
  • [EXTERNAL_DOWNLOADS]: The skill describes using npx to run the nightly version of the Chisel Solidity REPL (@foundry-rs/chisel@nightly), which involves downloading and executing code from the NPM registry. This represents a standard dependency acquisition for the toolset.
  • [COMMAND_EXECUTION]: The skill provides instructions for various CLI tools (forge, cast, anvil, chisel) that involve subprocess execution and interaction with the operating system and network.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 12:14 PM