stargate

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill is composed entirely of Markdown documentation files (SKILL.md, references/contracts.md, references/stargate-staking.md). There are no Python scripts, Node.js files, shell scripts, or binaries included in the package.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret user-provided queries regarding smart contract functions, staking tiers, and validator delegation. This represents a potential surface where malicious instructions could be embedded in user input to influence the agent's behavior. However, the risk is mitigated as the skill does not possess its own execution tools and relies on standard platform guardrails.
  • [EXTERNAL_DOWNLOADS]: The documentation references official VeChain resources, including GitHub repositories (github.com/vechain/stargate-contracts) and documentation sites (docs.stargate.vechain.org). These are verified vendor resources and do not represent a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:19 PM
Security Audit — agent-trust-hub — stargate