debank
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the external DeBank API, including human-readable transaction explanations and DeFi protocol details, which represents a potential surface for indirect prompt injection.
- Ingestion points: External blockchain data is fetched from the DeBank API endpoint (
pro-openapi.debank.com) within thetools/utils.pymodule and returned through theexports.pyinterface. - Boundary markers: Data retrieved from the API is passed to the agent without explicit delimiters or instructional boundary markers.
- Capability inventory: The skill utilizes network operations via
proxied_getandproxied_postfrom the platform'score.http_clientand possesses transaction simulation capabilities. - Sanitization: No sanitization or content filtering is performed on the strings returned from the DeBank API before they are processed by the agent.
- [DYNAMIC_EXECUTION]: The skill employs dynamic module loading to resolve its internal component structure.
- Evidence: The
exports.pyfile usesimportlib.util.spec_from_file_locationandloader.exec_moduleto load scripts from thetools/directory. This implementation is used to maintain module isolation and prevents the skill's modules from shadowing standard Python libraries such astokenorchain.
Audit Metadata