build-web3

Fail

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes a significant attack surface by ingesting and processing untrusted data from live blockchain networks through the call-rpc tool.
  • Ingestion points: Live blockchain data via call-rpc (e.g., in mcp-reference.md).
  • Boundary markers: While the instructions emphasize reading reference files before code generation, there are no specific prompt delimiters or instructions to ignore malicious data embedded in RPC responses.
  • Capability inventory: The skill facilitates file writing (scaffolding), network requests (Admin API, SQL Explorer), and shell command execution via the qn CLI.
  • Sanitization: The skill lacks explicit instructions for the agent to sanitize or validate external content retrieved from the blockchain before it is interpolated into prompts or used in code generation.
  • [COMMAND_EXECUTION]: The documentation provides instructions for the agent and user to install and execute various CLI tools and global packages.
  • Evidence: Instructions to install the Quicknode CLI via Homebrew (brew install quicknode/tap/qn) and the mppx global utility (npm install -g mppx).
  • Evidence: The skill includes various administrative and account management commands (e.g., qn auth login, qn endpoint create, qn tooling-access enable) that mutate provider resources.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external code and services for its primary functionality.
  • Evidence: Directs the user to add a remote Model Context Protocol (MCP) server located at https://mcp.quicknode.com/mcp.
  • Evidence: Recommends the installation of numerous external libraries including @quicknode/sdk, mppx, viem, and @solana/kit.
  • [SAFE]: Automated scanners flagged a documentation reference and a vendor-owned domain as malicious, but these are identified as vendor-specific resources.
  • Evidence: The file references/quicknode/ipfs-reference.md was flagged by a reputation scanner, likely due to the inclusion of placeholder IPFS gateway URLs (YOUR_GATEWAY.quicknode-ipfs.com) which are standard in Quicknode's IPFS product documentation.
  • Evidence: Phishing alerts were triggered for the quicknode-ipfs.com domain, which is a verified infrastructure domain for the skill's author.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 3 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 25, 2026, 05:12 PM
Security Audit — agent-trust-hub — build-web3