software-crypto-web3
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes developer templates that provide installation commands for well-known and reputable industry tools, such as Foundry, Rustup, and the Solana CLI. These are standard procedures for setting up blockchain development environments.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it is designed to analyze smart contract source code and external regulatory documentation. However, it incorporates security-first workflows and explicit threat modeling to guide the agent in safely processing this information.
- [CREDENTIALS_UNSAFE]: Security best practices are followed for secret management; code snippets and configuration templates use standard environment variable placeholders (e.g.,
${FIREBLOCKS_API_KEY}orprocess.env.DEPLOYER_PRIVATE_KEY) rather than hardcoded credentials. - [OBFUSCATION]: The skill uses Base64 encoding solely for the legitimate purpose of demonstrating how to embed SVG metadata directly into on-chain NFT contracts, which is a common pattern in Web3 development.
- [REMOTE_CODE_EXECUTION]: Development templates provide instructions for compiling and deploying smart contracts using established frameworks like Hardhat, Foundry, and Anchor. No unauthorized or silent remote code execution patterns were found.
Audit Metadata