radix

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill encourages security-first development practices, such as capability-based authorization using badges and AccessRules, and explicit modeling of asset flows to prevent double-accounting errors.
  • [COMMAND_EXECUTION]: The skill provides instructions for utilizing standard Radix development CLI tools including scrypto, resim, rtmc, and rtmd. These tools are used for local testing, simulation, and manifest compilation within the developer's environment.
  • [PROMPT_INJECTION]: The skill is designed to analyze and process user-provided source code (Scrypto) and transaction manifests (.rtm), creating a potential surface for indirect prompt injection.
    • Ingestion points: User-supplied manifest files and smart contract source code snippets.
    • Boundary markers: The skill does not define specific delimiters to isolate user-provided data from the agent's instructions.
    • Capability inventory: Utilization of command-line compilers and simulators to evaluate user input.
    • Sanitization: No explicit validation or sanitization procedures are described for user-provided manifest strings before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 07:18 AM
Security Audit — agent-trust-hub — radix