quicknode
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references several external packages and resources necessary for blockchain development. These include '@quicknode/sdk', '@solana/kit', and '@triton-one/yellowstone-grpc'. These originate from well-known organizations or the vendor ('sendaifun') and are standard dependencies for this domain.
- [COMMAND_EXECUTION]: The documentation provides standard setup instructions using 'npm install' for environment initialization. There are no signs of arbitrary command execution or suspicious piping of remote scripts (e.g., 'curl | bash').
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external blockchain data (transactions, logs, and NFT metadata) which represents an attack surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through 'rpc.getAccountInfo', gRPC streams, and Metaplex DAS API responses.
- Boundary markers: The skill includes explicit instructions for the agent to never ask for or accept private keys or secret keys, providing a behavioral safeguard.
- Capability inventory: The skill has the ability to make network requests ('fetch'), upload files to IPFS, and manage real-time data streams.
- Sanitization: The provided examples demonstrate JSON parsing but do not show explicit sanitization of string contents from blockchain metadata before processing.
- [SAFE]: The 'Malicious URL' alert for the QuickNode IPFS gateway ('quicknode-ipfs.com') is a typical reputation flag for public gateways often abused by third parties, but the gateway itself is a core, legitimate service of the infrastructure provider. The malware flag on 'SKILL.md' is likely a false positive triggered by the high density of code snippets and blockchain-specific strings.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata