chainlink-vrf-skill

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is configured to retrieve technical documentation and contract reference data from official Chainlink domains, including docs.chain.link and vrf.chain.link. It also provides instructions for installing verified smart contract libraries from the author's official GitHub repository and the npm registry.- [COMMAND_EXECUTION]: Includes instructions for utilizing bash tools (specifically curl) as a fallback mechanism to retrieve updated documentation from official vendor endpoints. This functionality is restricted to data retrieval from known-good domains.- [PROMPT_INJECTION]: The skill contains logic to analyze user-provided smart contract code for the purpose of identifying and blocking deprecated VRF patterns (V1/V2). This serves as a defensive measure to ensure the generated code is compatible with current infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 12:29 PM