blockchain-bitcoin
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill's instructions and reference files were scanned for patterns of behavior-override markers, role-play injections, and system prompt extraction attempts. No prompt injection attempts were detected in SKILL.md or the associated 17 reference documents.- [DATA_EXFILTRATION]: All files were analyzed for hardcoded credentials, sensitive system paths (e.g., SSH keys, AWS configs), and suspicious network operations. While code snippets demonstrate network connectivity (e.g., Stratum protocol and aiohttp examples), they are purely educational and contain no pre-configured malicious destinations or exfiltration logic.- [REMOTE_CODE_EXECUTION]: The skill does not contain any commands that download and execute external scripts or packages. No patterns of 'curl | bash' or dynamic evaluation of untrusted remote content were found.- [OBFUSCATION]: Analysis for Base64, hex encoding, homoglyphs, and zero-width characters was conducted. No obfuscated content was found that masks malicious instructions or hidden URLs. Technical constants and example data (e.g., PSBT headers) are present but legitimate.- [COMMAND_EXECUTION]: The skill provides technical information and code snippets but does not invoke arbitrary system commands or acquire excessive privileges (sudo/chmod). Dynamic context injection ('!command') is not used.- [SAFE]: The skill is a legitimate technical resource for blockchain engineering. The repetitive content in several 'Deep Dive' reference files appears to be structural boilerplate and does not introduce security vulnerabilities.
Audit Metadata