ethskills
Fail
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is designed to fetch and load supplementary instruction files from
https://ethskills.com/. This mechanism allows the agent to dynamically integrate remote content into its runtime context, which can alter its operational logic based on external resources. - [DATA_EXFILTRATION]: The skill contains instructions for transmitting agent-generated feedback data to an external API endpoint at
https://ethskills.com/api/feedback. While the skill advises the agent to seek user permission before sending, it establishes a functional path for data exfiltration to a domain outside the trusted infrastructure. - [PROMPT_INJECTION]: The architecture of this skill relies on fetching external 'skills' (markdown instructions) at runtime. This creates a significant surface for indirect prompt injection, as any content fetched from the remote server acts as trusted instructions that can override safety guardrails or manipulate agent behavior without being part of the original local skill set.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata