solidity-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a collection of educational markdown files providing instructions and references for auditing Solidity code. No malicious scripts, network exfiltration patterns, or obfuscated payloads were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user-provided Solidity source code, which constitutes an ingestion point for untrusted data. An attacker could attempt to influence the audit results by embedding hidden instructions within code comments or logic. However, the skill does not use high-risk tools or perform external network requests that could be leveraged for an exploit.
  • Ingestion points: User-provided smart contract source code, interfaces, and libraries as described in Phase 1 of the Core Audit Workflow in SKILL.md.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters to separate user code from agent instructions.
  • Capability inventory: The skill instructions focus on generating a markdown report and do not invoke any subprocesses, file-system writing, or network operations.
  • Sanitization: The instructions do not include specific sanitization steps for the input code before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:51 AM
Security Audit — agent-trust-hub — solidity-auditor