wallet

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches blockchain-related data, such as net worth and token lists, from established service providers including DeBank (pro-openapi.debank.com) and Birdeye (public-api.birdeye.so). These are recognized services in the blockchain ecosystem.
  • [COMMAND_EXECUTION]: The documentation in SKILL.md demonstrates how to invoke the skill's Python functions using python3 -c, which is the standard pattern for tool execution in this environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it processes data from external blockchain APIs, such as token names and transaction metadata, which could be controlled by third parties.
  • Ingestion points: Data is retrieved from external APIs in wallet_balance, wallet_sol_balance, and wallet_get_all_balances within exports.py and wallet.py.
  • Boundary markers: The skill does not implement specific boundary delimiters or explicit instructions for the model to ignore embedded data content during processing.
  • Capability inventory: The skill possesses transaction broadcast and message signing capabilities via wallet_transfer, wallet_sol_transfer, and wallet_sign.
  • Sanitization: External data is processed directly as JSON objects without specific character filtering or sanitization of string fields like token names.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — wallet