blockchain-security-auditor

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides scripts to automate the execution of smart contract analysis tools such as Slither, Mythril, and Echidna. This behavior is consistent with the skill's purpose as a security auditing tool and relies on industry-standard software.\n- [PROMPT_INJECTION]: The skill is designed to analyze untrusted third-party code and documentation, creating an inherent surface for indirect prompt injection.\n
  • Ingestion points: The agent reads and inventories contract source code, whitepapers, and documentation during the "Scope & Reconnaissance" and "Automated Analysis" steps defined in the skill.\n
  • Boundary markers: None. The skill does not explicitly define markers to separate untrusted data from instructions.\n
  • Capability inventory: The skill can execute CLI tools, write JSON/Markdown files, and read project contents.\n
  • Sanitization: The skill does not provide instructions to sanitize or escape the analyzed code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:36 AM
Security Audit — agent-trust-hub — blockchain-security-auditor