hyperlane
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates interaction with the Hyperlane protocol, which involves processing interchain messages.
- Ingestion points: The
handlefunction described inreferences/core-architecture.mdreceives a_messagebody from an external origin chain. - Boundary markers: The documentation mentions Interchain Security Modules (ISMs) for protocol-level verification, but does not provide specific boundary markers for preventing prompt injection within the message body when processed by an AI agent.
- Capability inventory: The skill provides tools for contract deployment, message dispatching, and relayer management.
- Sanitization: No specific sanitization of the message body for LLM safety is documented, which is a common surface for indirect prompt injection in interchain messaging apps.
- [SAFE]: The skill documents the requirement for a
HYP_KEYenvironment variable inreferences/features-relayer.md. This is a standard and expected configuration for blockchain relayers to sign delivery transactions and is documented correctly as a user-provided environment variable rather than a hardcoded credential. - [SAFE]: The CLI installation instructions in
references/features-cli.mduse standard package managers (npm,npx,pnpm) to install official packages from the@hyperlane-xyzscope, which is the established namespace for the Hyperlane protocol.
Audit Metadata