setup-cairo-contracts

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The project scaffolding section contains a command (curl ... | sh) that downloads a script from https://sh.starkup.sh and pipes it directly into the shell. While this is the official installation method for the Starknet toolchain, executing unverified remote code in a shell environment is a significant security risk.
  • [COMMAND_EXECUTION]: The skill instructs the user to execute the scarb new command for project initialization and scaffolding.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources from the starkup.sh installer domain and official openzeppelin Cairo contract libraries via the Scarb package manager, both of which are standard components for Starknet development.
Recommendations
  • HIGH: Downloads and executes remote code from: https://sh.starkup.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 12:20 PM
Security Audit — agent-trust-hub — setup-cairo-contracts