hyperlane

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates interaction with the Hyperlane protocol, which involves processing interchain messages.
  • Ingestion points: The handle function described in references/core-architecture.md receives a _message body from an external origin chain.
  • Boundary markers: The documentation mentions Interchain Security Modules (ISMs) for protocol-level verification, but does not provide specific boundary markers for preventing prompt injection within the message body when processed by an AI agent.
  • Capability inventory: The skill provides tools for contract deployment, message dispatching, and relayer management.
  • Sanitization: No specific sanitization of the message body for LLM safety is documented, which is a common surface for indirect prompt injection in interchain messaging apps.
  • [SAFE]: The skill documents the requirement for a HYP_KEY environment variable in references/features-relayer.md. This is a standard and expected configuration for blockchain relayers to sign delivery transactions and is documented correctly as a user-provided environment variable rather than a hardcoded credential.
  • [SAFE]: The CLI installation instructions in references/features-cli.md use standard package managers (npm, npx, pnpm) to install official packages from the @hyperlane-xyz scope, which is the established namespace for the Hyperlane protocol.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 12:14 PM