x-2-earn-apps
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: No malicious patterns were identified. The skill focuses on providing legitimate technical documentation and best practices for the VeBetterDAO developer ecosystem.
- [INDIRECT_PROMPT_INJECTION]: The skill manages the attack surface associated with processing untrusted user data (e.g., sustainability proofs) by defining verification protocols. Ingestion points: Users submit image URLs and external links as proof of sustainable actions, as documented in sustainability-proofs.md and ai-image-validation.md. Boundary markers: The ai-image-validation.md guide provides a structured, multi-stage AI prompt designed to extract objective authenticity signals and return structured JSON, reducing the risk of the model following instructions embedded within the user data. Capability inventory: The skill uses contract interaction capabilities to call distributeReward functions on the blockchain. Sanitization: Verification logic includes AI-based fraud detection, threshold-based manual review flags, and integration with third-party risk assessment services like Guardian.
- [EXTERNAL_DOWNLOADS]: The skill references official ecosystem resources, including NPM packages (@vechain/sdk-network, @vechain/vebetterdao-contracts) and official GitHub repositories for contract implementations and project templates. These are legitimate dependencies for the stated purpose.
Audit Metadata