debank

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the external DeBank API, including human-readable transaction explanations and DeFi protocol details, which represents a potential surface for indirect prompt injection.
  • Ingestion points: External blockchain data is fetched from the DeBank API endpoint (pro-openapi.debank.com) within the tools/utils.py module and returned through the exports.py interface.
  • Boundary markers: Data retrieved from the API is passed to the agent without explicit delimiters or instructional boundary markers.
  • Capability inventory: The skill utilizes network operations via proxied_get and proxied_post from the platform's core.http_client and possesses transaction simulation capabilities.
  • Sanitization: No sanitization or content filtering is performed on the strings returned from the DeBank API before they are processed by the agent.
  • [DYNAMIC_EXECUTION]: The skill employs dynamic module loading to resolve its internal component structure.
  • Evidence: The exports.py file uses importlib.util.spec_from_file_location and loader.exec_module to load scripts from the tools/ directory. This implementation is used to maintain module isolation and prevents the skill's modules from shadowing standard Python libraries such as token or chain.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — debank