sp3nd

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes product URLs from external marketplaces and data from API responses. These external inputs could potentially contain malicious instructions intended to influence the agent's behavior.
  • Ingestion points: Product URLs (product_url) provided to the cart creation endpoint and response data from the SP3ND API.
  • Boundary markers: None present in the instructions to delimit external data from agent instructions.
  • Capability inventory: The skill has access to sensitive capabilities including blockchain transaction signing (wallet_sol_sign_transaction) and network communication via urllib.request.
  • Sanitization: No explicit sanitization or validation steps for external URLs or API responses are described.
  • [EXTERNAL_DOWNLOADS]: The skill documentation recommends the installation of the solders and solana Python packages, which are standard libraries for interacting with the Solana blockchain.
  • [DATA_EXFILTRATION]: The skill collects and transmits user-provided shipping details (name, address, phone number) to the SP3ND service to facilitate order fulfillment. It also constructs and broadcasts signed blockchain transactions to the Solana network to complete payments. These operations are core to the skill's stated purpose of facilitating autonomous commerce.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — sp3nd