stacks
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the Stacks blockchain and P2P network, which constitutes an attack surface for indirect instructions embedded in transaction data or event payloads.
- Ingestion points: The skill interacts with external data via various RPC endpoints (e.g.,
GET /v2/accounts,GET /v3/blocks) and the Event Observer system (/new_block,/new_mempool_tx,/stackerdb_chunks) described inreferences/core-rpc-endpoints.mdandreferences/features-event-dispatcher.md. - Boundary markers: There are no explicit instructions or boundary markers defined to help the agent distinguish between trusted instructions and potentially untrusted data retrieved from the blockchain.
- Capability inventory: The skill leverages
cargo runfor binary execution,curlfor network requests, and shell redirects for creating local transaction files. - Sanitization: The documentation does not describe any specific validation or sanitization mechanisms for the data received from the blockchain before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill instructions rely heavily on the local execution of binaries through the Rust toolchain to manage the node and interact with the network.
- Evidence: Multiple reference files, such as
references/core-testnet-transactions.mdandreferences/advanced-profiling.md, instruct the agent to usecargo runto executeblockstack-cli,stacks-node, andstacks-inspect. - [PRIVILEGE_ESCALATION]: Documentation for performance analysis suggests the use of elevated privileges to access system-level profiling information.
- Evidence: In
references/advanced-profiling.md, the instructions for generating flame graphs on macOS specify the use of the--rootflag with theflamegraphutility, which is a standard method for granting the necessary permissions to DTrace for kernel-level profiling.
Audit Metadata