smart-contract-audit
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external, untrusted smart contract code, creating a surface for indirect prompt injection.
- Ingestion points: Smart contract source files (Solidity, Vyper, Move, Cairo) provided for review as specified in SKILL.md.
- Boundary markers: The instructions do not define specific delimiters or boundary markers to separate untrusted code from internal instructions.
- Capability inventory: The workflow suggests the use of analysis tools like Slither, Mythril, and Foundry that interact with the provided code.
- Sanitization: There are no explicit instructions for the agent to sanitize or escape the contract content before processing it.
Audit Metadata