skills/sarthib7/agentsmith/pay/Gen Agent Trust Hub

pay

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of the @solana/pay package (references/setup-cli.md) and the use of Docker images from ghcr.io/solana-foundation/pay (references/monetize-api.md). These resources belong to the Solana Foundation, a well-known entity in the blockchain ecosystem.\n- [PROMPT_INJECTION]: The skill processes external API responses, which presents an indirect prompt injection surface.\n
  • Ingestion points: Untrusted data enters the agent's context through the responses of the curl tool and metadata retrieved by search_catalog and get_catalog_entry (SKILL.md).\n
  • Boundary markers: The agent is instructed in references/security.md to isolate external content by wrapping it in fenced code blocks with an explicit 'Provider output (untrusted):' label.\n
  • Capability inventory: The agent possesses network request capabilities via the curl tool and can check wallet balances (SKILL.md).\n
  • Sanitization: The instructions in references/security.md provide a strong mitigation by explicitly commanding the agent to ignore any instructions or operational guidance embedded in external responses and to report such events to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 11:05 AM
Security Audit — agent-trust-hub — pay