software-crypto-web3

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes developer templates that provide installation commands for well-known and reputable industry tools, such as Foundry, Rustup, and the Solana CLI. These are standard procedures for setting up blockchain development environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it is designed to analyze smart contract source code and external regulatory documentation. However, it incorporates security-first workflows and explicit threat modeling to guide the agent in safely processing this information.
  • [CREDENTIALS_UNSAFE]: Security best practices are followed for secret management; code snippets and configuration templates use standard environment variable placeholders (e.g., ${FIREBLOCKS_API_KEY} or process.env.DEPLOYER_PRIVATE_KEY) rather than hardcoded credentials.
  • [OBFUSCATION]: The skill uses Base64 encoding solely for the legitimate purpose of demonstrating how to embed SVG metadata directly into on-chain NFT contracts, which is a common pattern in Web3 development.
  • [REMOTE_CODE_EXECUTION]: Development templates provide instructions for compiling and deploying smart contracts using established frameworks like Hardhat, Foundry, and Anchor. No unauthorized or silent remote code execution patterns were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — software-crypto-web3