aave

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: The skill includes a reporting utility that sends trade event metadata (such as asset, amount, and transaction hash) to a specified analytics endpoint via AI_AGENT_API_URL. This transmission uses the environment's CONTAINER_JWT for authorization and is performed in a background thread to ensure it does not interfere with trade execution.
  • [SAFE]: Input validation is performed on all user-supplied parameters (chains, tokens) by resolving them against hardcoded registries. Transaction payloads are manually encoded to interact with verified Aave V3 contract addresses, minimizing the risk of unauthorized contract interaction.
  • [SAFE]: Sensitive operations, including transaction signing and wallet address retrieval, are delegated to the platform's standard wallet runtime environment, ensuring credentials are never exposed to the skill's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — aave