alchemy-api
Pass
Audited by Gen Agent Trust Hub on Mar 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of documentation and integration guides for official Alchemy blockchain services.
- [SAFE]: All network operations documented use official vendor domains (e.g., eth-mainnet.g.alchemy.com, api.g.alchemy.com) or trusted placeholders for API keys.
- [SAFE]: Secret management follows industry standards by instructing users to utilize environment variables ($ALCHEMY_API_KEY) rather than hardcoding credentials.
- [SAFE]: The documentation identifies potential indirect prompt injection vectors (e.g., untrusted NFT metadata) and provides explicit remediation guidance, such as sanitizing and proxying external content.
- [SAFE]: Webhook integration examples include robust security measures, such as HMAC signature verification using standard cryptographic libraries.
Audit Metadata