scv-scan

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external, untrusted Solidity codebases, which creates an attack surface for indirect prompt injection attacks.
  • Ingestion points: The agent ingests external Solidity source code using the Read, Grep, and Glob tools during the codebase sweep and deep validation phases.
  • Boundary markers: The instructions do not define delimiters or provide specific instructions for the agent to ignore any natural language commands that might be found within code comments or string literals in the audited files.
  • Capability inventory: The skill environment includes powerful tools such as Bash (for command execution) and Write (for file system access), which could be misused if an injection attack successfully overrides the agent's instructions.
  • Sanitization: No sanitization, escaping, or validation logic is prescribed for the data read from external files before it is processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 09:45 PM
Security Audit — agent-trust-hub — scv-scan