build-web3
Fail
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exposes a significant attack surface by ingesting and processing untrusted data from live blockchain networks through the
call-rpctool. - Ingestion points: Live blockchain data via
call-rpc(e.g., inmcp-reference.md). - Boundary markers: While the instructions emphasize reading reference files before code generation, there are no specific prompt delimiters or instructions to ignore malicious data embedded in RPC responses.
- Capability inventory: The skill facilitates file writing (scaffolding), network requests (Admin API, SQL Explorer), and shell command execution via the
qnCLI. - Sanitization: The skill lacks explicit instructions for the agent to sanitize or validate external content retrieved from the blockchain before it is interpolated into prompts or used in code generation.
- [COMMAND_EXECUTION]: The documentation provides instructions for the agent and user to install and execute various CLI tools and global packages.
- Evidence: Instructions to install the Quicknode CLI via Homebrew (
brew install quicknode/tap/qn) and themppxglobal utility (npm install -g mppx). - Evidence: The skill includes various administrative and account management commands (e.g.,
qn auth login,qn endpoint create,qn tooling-access enable) that mutate provider resources. - [EXTERNAL_DOWNLOADS]: The skill relies on external code and services for its primary functionality.
- Evidence: Directs the user to add a remote Model Context Protocol (MCP) server located at
https://mcp.quicknode.com/mcp. - Evidence: Recommends the installation of numerous external libraries including
@quicknode/sdk,mppx,viem, and@solana/kit. - [SAFE]: Automated scanners flagged a documentation reference and a vendor-owned domain as malicious, but these are identified as vendor-specific resources.
- Evidence: The file
references/quicknode/ipfs-reference.mdwas flagged by a reputation scanner, likely due to the inclusion of placeholder IPFS gateway URLs (YOUR_GATEWAY.quicknode-ipfs.com) which are standard in Quicknode's IPFS product documentation. - Evidence: Phishing alerts were triggered for the
quicknode-ipfs.comdomain, which is a verified infrastructure domain for the skill's author.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 3 malicious URL(s) - DO NOT USE
Audit Metadata