mantle
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill configuration and reference files (assets/registry.json and references/curated-defaults.yaml) reference 'https://docs.merchantmoe.com/resources/contracts' as a source for verified contract addresses. This URL has been flagged by automated security scans as a confirmed malicious site associated with cryptocurrency scams (CryptScam).
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the 'mantle-cli' tool directly from a non-whitelisted GitHub repository (github:mantle-xyz/mantle-agent-scaffold) via 'npm install'. This practice bypasses package registry verification and introduces supply chain risk from a source not included in the trusted organization list.
- [REMOTE_CODE_EXECUTION]: By requiring the installation and execution of code from an unverified remote GitHub repository to perform core tasks, the skill facilitates potential remote code execution.
- [INDIRECT_PROMPT_INJECTION]: The 'mantle-data-indexer' skill features an indirect prompt injection surface through the ingestion of user-supplied SQL and GraphQL queries. 1. Ingestion point: user input mapped to queries in skills/mantle-data-indexer/SKILL.md. 2. Boundary markers: Absent for the query strings. 3. Capability inventory: mantle-cli commands for network and database access. 4. Sanitization: Absent for user-provided query content.
Recommendations
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata