flare-fdc

Pass

Audited by Gen Agent Trust Hub on Mar 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified due to the skill's primary purpose of handling external data attestations.
  • Ingestion points: The skill guides users on processing responseBody and response_hex from FDC attestations, including arbitrary public Web2 content from the Web2Json type.
  • Boundary markers: The skill includes a dedicated "Security and usage considerations" section in SKILL.md that explicitly warns against passing external data into prompts or allowing it to influence agent behavior.
  • Capability inventory: This is an informational skill with no associated executable scripts or subprocess capabilities.
  • Sanitization: The documentation provides clear guidance to decode and use data only according to the documented format and expected ABI/schema.
  • [SAFE]: References to external resources are limited to official vendor-controlled domains and repositories.
  • Trusted Sources: All GitHub references target github.com/flare-foundation/ and documentation links target dev.flare.network.
  • Package Management: Mentions installation of the vendor-owned package @flarenetwork/flare-wagmi-periphery-package.
  • Credential Handling: References to environment variables like VERIFIER_API_KEY_TESTNET in SKILL.md use safe UUID placeholders (00000000-0000-0000-0000-000000000000).
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 16, 2026, 01:57 PM