across-protocol-ai-agent-skill

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection through the 'Embedded Crosschain Actions' and 'Suggested Fees' features. These allow for the execution of arbitrary contract calls or messages on destination chains based on user-supplied data.
  • Ingestion points: User instructions containing transaction targets, function signatures, or cross-chain messages in embedded-actions.md and suggested-fees-api.md.
  • Boundary markers: Absent from the skill's instructional prompt logic.
  • Capability inventory: Construction of executable transaction calldata for the Across Protocol API.
  • Sanitization: The security.md file provides clear remediation guidance, requiring validation of all target addresses and sanitization of user-controlled inputs.
  • [EXTERNAL_DOWNLOADS]: References official and well-known resources provided by the vendor.
  • Evidence: Mentions the @across-protocol/app-sdk Node.js package and official API domains app.across.to and testnet.across.to.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 11:20 AM