sablier-create-airdrop
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior or security vulnerabilities were identified in the skill's instructions or source code.\n- [COMMAND_EXECUTION]: Transaction execution is handled by Foundry's
casttool. The skill enforces the use of the--browserflag to delegate signing to the user's wallet extension, preventing sensitive credentials from being handled by the agent.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes the Pinata v3 API for IPFS storage of campaign data. Pinata is a well-known service, and the interaction is restricted to standard authenticated file uploads.\n- [DATA_EXFILTRATION]: The skill processes user-provided CSV data to create airdrop campaigns. This data flow is documented and necessary for functionality, with no evidence of unauthorized transmission to external parties.\n- [PROMPT_INJECTION]: The skill instructions are declarative and functional; they do not include any patterns typical of prompt injection, such as instructions to override safety guidelines.
Audit Metadata