blockchain-security-auditor
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides scripts to automate the execution of smart contract analysis tools such as Slither, Mythril, and Echidna. This behavior is consistent with the skill's purpose as a security auditing tool and relies on industry-standard software.\n- [PROMPT_INJECTION]: The skill is designed to analyze untrusted third-party code and documentation, creating an inherent surface for indirect prompt injection.\n
- Ingestion points: The agent reads and inventories contract source code, whitepapers, and documentation during the "Scope & Reconnaissance" and "Automated Analysis" steps defined in the skill.\n
- Boundary markers: None. The skill does not explicitly define markers to separate untrusted data from instructions.\n
- Capability inventory: The skill can execute CLI tools, write JSON/Markdown files, and read project contents.\n
- Sanitization: The skill does not provide instructions to sanitize or escape the analyzed code.
Audit Metadata