ethena

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches real-time yield and pool data from DefiLlama (yields.llama.fi) and queries blockchain state using a public Ethereum RPC node (ethereum.publicnode.com). These are well-known technology services and represent standard integration for DeFi applications.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources (Ethereum RPC and DefiLlama API) which could theoretically contain malicious payloads.
  • Ingestion points: External data is ingested in exports.py via _eth_call (RPC) and proxied_get (DefiLlama).
  • Boundary markers: The instructions do not define specific delimiters for external data, though the data is typically processed as numeric values.
  • Capability inventory: The skill can generate transaction calldata and perform network operations.
  • Sanitization: Blockchain responses are converted from hex to integers, and user-supplied amounts are validated using Decimal and to_wei helpers to ensure numeric integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — ethena