blockchain-security

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an Indirect Prompt Injection surface (Category 8).
  • Ingestion points: SKILL.md directs the agent to analyze external "Smart contracts or protocol" and "Codebase location" provided by users or fetched from remote repositories.
  • Boundary markers: Absent. The instructions do not define delimiters or provide warnings to the agent to ignore instructions embedded in the analyzed contracts.
  • Capability inventory: The skill leverages security tools such as Slither, Mythril, Aderyn, Halmos, and Semgrep through the agent's shell capability, and provides guidance for automated analysis pipelines.
  • Sanitization: Absent. Untrusted external data is passed to local tools and potentially interpolated into the agent's prompt during analysis.
  • [PROMPT_INJECTION]: Extreme structural redundancy and filler text (bloat) are present in nine reference files (architecture-patterns.md, code-organization.md, deployment-pipelines.md, error-handling.md, performance-optimization.md, security-best-practices.md, state-management.md, testing-strategies.md). Each file contains 150 sections of repetitive OS engineering filler unrelated to the primary blockchain security purpose. This volume of noise acts as structural obfuscation to hinder human review.
  • [EXTERNAL_DOWNLOADS]: The skill neutrally references several external services and tools for security analysis and monitoring.
  • Tenderly API: references/incident-response.md provides examples for simulating exploits via api.tenderly.co.
  • Security Tools: Mentions official platforms like Immunefi, Code4rena, Sherlock, and Hats Finance.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 12:24 PM
Security Audit — agent-trust-hub — blockchain-security