orderly-deposit-withdraw

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API endpoints (such as /v1/public/token and /v1/withdraw_nonce) and user-supplied inputs (amounts and wallet addresses) to drive sensitive financial transactions. Without explicit boundary markers or sanitization, there is a risk that malicious data could influence the agent's behavior.
  • Ingestion points: Data enters the agent context through hooks like useChain, useDeposit, and direct REST API calls described in SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded content within API responses are implemented.
  • Capability inventory: The skill is capable of executing blockchain transactions (e.g., usdc.approve, vault.deposit) and signing withdrawal/transfer messages.
  • Sanitization: The provided code snippets do not demonstrate validation or sanitization of the input data before it is used in transaction construction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 01:22 PM
Security Audit — agent-trust-hub — orderly-deposit-withdraw