sablier-create-airdrop

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behavior or security vulnerabilities were identified in the skill's instructions or source code.\n- [COMMAND_EXECUTION]: Transaction execution is handled by Foundry's cast tool. The skill enforces the use of the --browser flag to delegate signing to the user's wallet extension, preventing sensitive credentials from being handled by the agent.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes the Pinata v3 API for IPFS storage of campaign data. Pinata is a well-known service, and the interaction is restricted to standard authenticated file uploads.\n- [DATA_EXFILTRATION]: The skill processes user-provided CSV data to create airdrop campaigns. This data flow is documented and necessary for functionality, with no evidence of unauthorized transmission to external parties.\n- [PROMPT_INJECTION]: The skill instructions are declarative and functional; they do not include any patterns typical of prompt injection, such as instructions to override safety guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 11:17 AM