token-integration-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is intended to analyze untrusted smart contract source code and external blockchain data, creating a surface for indirect prompt injection attacks.\n
  • Ingestion points: User-supplied contract codebase files and on-chain data retrieved via RPC endpoints.\n
  • Boundary markers: The skill does not specify explicit delimiters or 'ignore' instructions for the external content it ingests.\n
  • Capability inventory: The skill is capable of executing shell commands (Slither, Echidna) and performing network requests to RPC nodes.\n
  • Sanitization: No sanitization or safety-filtering logic is described for the code being analyzed.\n- [COMMAND_EXECUTION]: The skill orchestrates the use of security analysis tools including slither, slither-check-erc, slither-prop, and echidna. These tools are legitimate and were developed by the skill's author, Trail of Bits.\n- [EXTERNAL_DOWNLOADS]: The skill references and utilizes standard, well-known blockchain interaction libraries like web3.js and ethers.js for scarcity analysis and configuration verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:17 PM
Security Audit — agent-trust-hub — token-integration-analyzer