mantle

Fail

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configuration and reference files (assets/registry.json and references/curated-defaults.yaml) reference 'https://docs.merchantmoe.com/resources/contracts' as a source for verified contract addresses. This URL has been flagged by automated security scans as a confirmed malicious site associated with cryptocurrency scams (CryptScam).
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the 'mantle-cli' tool directly from a non-whitelisted GitHub repository (github:mantle-xyz/mantle-agent-scaffold) via 'npm install'. This practice bypasses package registry verification and introduces supply chain risk from a source not included in the trusted organization list.
  • [REMOTE_CODE_EXECUTION]: By requiring the installation and execution of code from an unverified remote GitHub repository to perform core tasks, the skill facilitates potential remote code execution.
  • [INDIRECT_PROMPT_INJECTION]: The 'mantle-data-indexer' skill features an indirect prompt injection surface through the ingestion of user-supplied SQL and GraphQL queries. 1. Ingestion point: user input mapped to queries in skills/mantle-data-indexer/SKILL.md. 2. Boundary markers: Absent for the query strings. 3. Capability inventory: mantle-cli commands for network and database access. 4. Sanitization: Absent for user-provided query content.
Recommendations
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — mantle