botchain-paymaster

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides technical documentation and integration steps for BOT Chain's EOA Paymaster (BEP-414) and ERC-4337 bundlers.
  • [EXTERNAL_DOWNLOADS]: The skill references official developer documentation (dev-docs.botchain.ai), specific blockchain specifications (github.com/bnb-chain/BEPs), and official infrastructure providers (nodereal.io). These are legitimate, well-known service providers in the blockchain ecosystem and do not constitute a security risk.
  • [PROMPT_INJECTION]: The SKILL.md includes a source constraint note requiring information to be pulled from specific official domains. While this is an instruction to the model, it is a benign grounding constraint intended for data accuracy rather than an attempt to bypass safety filters or override agent behavior.
  • [COMMAND_EXECUTION]: A benign curl example is provided to demonstrate how to query the official bundler RPC. This is standard technical documentation for a developer-oriented skill and does not include unsafe piping or remote execution.
  • [DATA_EXFILTRATION]: No sensitive file paths, credential extraction patterns, or exfiltration to unknown domains were detected. The infrastructure URLs provided (bundler.botchain.ai, bundler.bohr.life) are the primary purpose of the skill and match the vendor context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 02:13 AM
Security Audit — agent-trust-hub — botchain-paymaster