NYC
skills/bankrbot/openclaw-skills/yoink/Gen Agent Trust Hub

yoink

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION] (SAFE): The skill provides command templates for querying the blockchain using curl and jq. These are standard operations for retrieving data and do not involve executing untrusted remote scripts.
  • [DATA_EXFILTRATION] (LOW): The skill performs network requests to mainnet.base.org via curl. As this domain is not on the provided whitelist, it is flagged as LOW severity, although it is a standard infrastructure endpoint for the Base network and is required for the skill's primary purpose.
  • [INDIRECT_PROMPT_INJECTION] (LOW): A vulnerability surface for indirect prompt injection exists. Ingestion points: Data returned from public RPC calls to the Base mainnet. Boundary markers: None specified in the instructions. Capability inventory: Arbitrary transaction submission via Bankr and network queries via curl. Sanitization: No sanitization or validation of the external blockchain data is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:15 PM