orderly-deposit-withdraw
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API endpoints (such as /v1/public/token and /v1/withdraw_nonce) and user-supplied inputs (amounts and wallet addresses) to drive sensitive financial transactions. Without explicit boundary markers or sanitization, there is a risk that malicious data could influence the agent's behavior.
- Ingestion points: Data enters the agent context through hooks like useChain, useDeposit, and direct REST API calls described in SKILL.md.
- Boundary markers: No specific delimiters or instructions to ignore embedded content within API responses are implemented.
- Capability inventory: The skill is capable of executing blockchain transactions (e.g., usdc.approve, vault.deposit) and signing withdrawal/transfer messages.
- Sanitization: The provided code snippets do not demonstrate validation or sanitization of the input data before it is used in transaction construction.
Audit Metadata