building-secure-contracts
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and analyze untrusted codebase content for security vulnerabilities. This creates an inherent surface where malicious instructions hidden in a user's project files could attempt to influence the agent's behavior during analysis. Mandatory Evidence: 1. Ingestion points: Contract source files (.sol, .cairo, .rs, .go, .teal, .fc) and documentation files. 2. Boundary markers: No explicit delimiters are used to wrap codebase content. 3. Capability inventory: The skill calls subprocesses (Slither, Caracal, Tealer), reads the filesystem, and can perform on-chain network queries. 4. Sanitization: No content-specific sanitization or escaping was identified.
- [EXTERNAL_DOWNLOADS]: The skill suggests the installation of well-known security tools like Caracal and Tealer from reputable sources. These tools are standard in the smart contract security ecosystem.
- [COMMAND_EXECUTION]: The skill facilitates the execution of various static analysis and development commands (e.g., slither, caracal, tealer, cargo build, anchor test). These executions are consistent with the skill's primary purpose of providing security auditing and development guidance.
Audit Metadata