secure-workflow-guide
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of various security analysis tools via the shell, including Slither and its suite of checkers. These commands are used to scan the local codebase for vulnerabilities, verify ERC conformance, and generate visual inheritance and function graphs.
- [PROMPT_INJECTION]: The workflow involves processing external data (the user's smart contract codebase), which inherently creates a surface for indirect prompt injection. Maliciously crafted comments or code could theoretically attempt to influence the agent's summary or recommendations, though this is a standard risk for analysis tools and is mitigated by the structured nature of the reported output.
- [SAFE]: The skill does not perform any unauthorized data exfiltration, use obfuscated code, or establish suspicious network connections. All referenced tools and resources are well-known within the smart contract security community.
Audit Metadata