code-review-solidity
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external, untrusted source code (Solidity files, Foundry/Hardhat projects).
- Ingestion points: Source code files (.sol) and project configuration data are processed by the agent during the audit process.
- Boundary markers: The instructions lack specific delimiters or negative constraints to prevent the agent from potentially interpreting instructions embedded within smart contract comments or metadata as authoritative commands.
- Capability inventory: The skill leverages security analysis tools including slither, mythril, and foundry to interact with the provided code.
- Sanitization: No explicit sanitization or pre-processing steps are defined to neutralize potential prompt injection payloads hidden in the target codebase before analysis.
Audit Metadata