smart-contract-vulnerabilities

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill provides a professional playbook for auditing Solidity contracts, including conceptual explanations and side-by-side vulnerable vs. fixed code patterns.
  • [PROMPT_INJECTION]: The skill is designed to analyze untrusted Solidity and EVM smart contract source code, which constitutes an ingestion point for indirect prompt injection. 1. Ingestion points: Audited smart contract code provided for security review (SKILL.md). 2. Boundary markers: The skill relies on standard markdown delimiters but does not specify defensive prompt instructions to ignore embedded code commands. 3. Capability inventory: The skill references external tools such as Slither, Mythril, and Foundry for analysis. 4. Sanitization: The skill does not perform automated sanitization of the input code.
  • [COMMAND_EXECUTION]: The skill lists common CLI usage patterns for auditing tools like Slither, Mythril, and Foundry (e.g., 'slither .', 'myth analyze'). These are provided for developer reference and are not automatically executed by the skill environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — smart-contract-vulnerabilities