borrow-integration

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and review external codebases, UI copy, and integration artifacts. This creates a surface where malicious instructions could be embedded in the data being audited (e.g., in code comments or UI strings). However, the skill provides specific rubrics and instructions for the agent to maintain a focused audit role, which is a standard behavior for auditing tools and is considered safe in this context.
  • [EXTERNAL_DOWNLOADS]: The skill references official Morpho SDKs (@morpho-org/blue-sdk, @morpho-org/morpho-ts, @morpho-org/midnight-sdk) and APIs (Morpho GraphQL API, MCP server). These are well-known vendor-owned resources used for protocol interaction and are documented neutrally as intended functional dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 07:30 PM
Security Audit — agent-trust-hub — borrow-integration