celopedia-skill

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an official technical reference for the Celo blockchain ecosystem, authored by 'celo-org'. It provides developers with validated contract addresses and architectural guides for building on the network.
  • [EXTERNAL_DOWNLOADS]: The skill references several official NPM and PyPI packages (e.g., '@celo/identity', 'celo-mcp') and well-known technology services (e.g., DefiLlama API, The Grid GraphQL). These external references are standard for the developer use-cases described and originate from trusted or authoritative sources within the Celo ecosystem.
  • [COMMAND_EXECUTION]: The documentation includes standard CLI usage for developer tools such as 'forge', 'hardhat', 'celocli', and 'gh'. These are instructional examples meant for manual execution by developers and do not involve silent or malicious execution patterns.
  • [CREDENTIALS_SAFE]: Code templates correctly use environment variables (e.g., 'PRIVATE_KEY', 'CELOSCAN_API_KEY') and placeholders, adhering to security best practices for secret management in development environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to fetch live data from external APIs (governance proposals, grant programs). While this represents an ingestion surface for untrusted data, the skill is scoped to purely informative synthesis of that data, and no exploitable capabilities (like 'eval' or system shell access) are provided to the agent to act upon potentially malicious data content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 09:02 AM