Bankr Agent - Arbitrary Transactions

Fail

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • **Ind i r e c t P r o m p t I n j e c t i o n ( H I G H ) : * * T h i s s k i l l p r o c e s s e s u n t r u s t e d t r a n s a c t i o n p a r a m e t e r s ( ' t o ' , ' d a t a ' , ' v a l u e ' ) w h i c h c a n b e s u p p l i e d b y a n a t t a c k e r v i a i n g e s t e d d a t a t o m a n i p u l a t e a g e n t b e h a v i o r . * I n g e s t i o n p o i n t s : U s e r
  • p r o v i d e d t r a n s a c t i o n J S O N i n t h e s k i l l d e f i n i t i o n . * B o u n d a r y m a r k e r s : A b s e n t ; t h e r e a r e n o i n s t r u c t i o n s t o v e r i f y t h e s a f e t y o f t h e t r a n s a c t i o n d e s t i n a t i o n o r p a y l o a d . * C a p a b i l i t y i n v e n t o r y : H i g h
  • p r i v i l e g e w r i t e c a p a b i l i t y t o e x e c u t e o n
  • c h a i n t r a n s a c t i o n s . * S a n i t i z a t i o n : V a l i d a t i o n r u l e s o n l y c h e c k h e x f o r m a t t i n g a n d f a i l t o v a l i d a t e t h e i n t e n t o f t h e s m a r t c o n t r a c t i n t e r a c t i o n .
  • **Pr i v i l e g e E s c a l a t i o n ( H I G H ) : * * T h e s k i l l f a c i l i t a t e s h i g h
  • s t a k e s f i n a n c i a l o p e r a t i o n s w i t h o u t s u f f i c i e n t g u a r d r a i l s . T h e e x a m p l e s d e m o n s t r a t e ' a p p r o v e ' t r a n s a c t i o n s ( 0 x 0 9 5 e a 7 b 3 ) , w h i c h i s a s t a n d a r d v e c t o r f o r d r a i n i n g u s e r w a l l e t s i f t h e s p e n d e r i s a m a l i c i o u s c o n t r a c t .
  • **Dy n a m i c E x e c u t i o n ( M E D I U M ) : * * E x e c u t i n g a r b i t r a r y E V M c a l l d a t a i s f u n c t i o n a l l y e q u i v a l e n t t o r u n t i m e c o d e i n j e c t i o n o n t h e t a r g e t b l o c k c h a i n , w h e r e t h e l o g i c i s d e f i n e d b y u n t r u s t e d i n p u t .
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 15, 2026, 06:45 PM